<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Portals/Gateways in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435984#M1808</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38148"&gt;@GFN182&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use groups in your security policy.&amp;nbsp; You will need to configure group mapping, but with groups a single user can match multiple security policy rules.&amp;nbsp; The user does not have to change gateways for different access rights.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 22 Sep 2021 19:32:43 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-09-22T19:32:43Z</dc:date>
    <item>
      <title>Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435944#M1802</link>
      <description>&lt;P&gt;GP on the fw is setup and working. I have a group of users i need to isolate from everyone else - most of the time.So if they use the url vpn1.mydomain.com they get IP Pool X and specific X policies. If they use url vpn2.mydomain.com they get IP Pool Y and specific Y policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like i should be able to setup multiple portals and gateways on an interface but i want some confirmation before i start working with a production environment.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 18:25:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435944#M1802</guid>
      <dc:creator>GFN182</dc:creator>
      <dc:date>2021-09-22T18:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435961#M1803</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38148"&gt;@GFN182&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The straightforward solution is to use source user in the security policy to isolate the users without having to build multiple gateways.&amp;nbsp; GP has User-ID built-in.&amp;nbsp; I like keeping all of my security configuration in one place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 18:56:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435961#M1803</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-22T18:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435975#M1804</link>
      <description>&lt;P&gt;I would go with&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;suggestion.&lt;/P&gt;&lt;P&gt;just one portal with one gateway, then the gateway can have many configs that can differentiate between users vi user-id and distribute ip as required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or just have the same gateway for all and base your policies on user-id only.....&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:15:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435975#M1804</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-09-22T19:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435981#M1805</link>
      <description>&lt;P&gt;Unfortunately the same user Id has multiple requirements.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:20:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435981#M1805</guid>
      <dc:creator>GFN182</dc:creator>
      <dc:date>2021-09-22T19:20:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435982#M1806</link>
      <description>&lt;P&gt;Unless the authentication needs to be different, you can definitely stick to one portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each gateway can have multiple configurations based on user group membership so you can assign different subnets to each user group.&lt;/P&gt;&lt;P&gt;In addition you can reuse those user groups in security rules to limit which access each group gets&lt;/P&gt;&lt;P&gt;If they need to be able to choose when they take certain access, you can set up 2 gateways on the one portal and allow them to pick which one to connect to manually. You can then assign them one IP pool on one gateway and another on the second gateway, then set security rules that allow them access based on user group and source subnet&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:24:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435982#M1806</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-09-22T19:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435983#M1807</link>
      <description>&lt;P&gt;I’m not sure why you would want to do that... &amp;nbsp;could you explain why as it may assist in finding another solutiom.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:26:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435983#M1807</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-09-22T19:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435984#M1808</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38148"&gt;@GFN182&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use groups in your security policy.&amp;nbsp; You will need to configure group mapping, but with groups a single user can match multiple security policy rules.&amp;nbsp; The user does not have to change gateways for different access rights.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435984#M1808</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-22T19:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435990#M1810</link>
      <description>&lt;P&gt;The use case is mutually exclusive. One connection will login to our isolated cyber environment. The other connection will give access to our production environment.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:57:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435990#M1810</guid>
      <dc:creator>GFN182</dc:creator>
      <dc:date>2021-09-22T19:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435991#M1811</link>
      <description>&lt;P&gt;Except i would belong to both groups&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 19:58:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/435991#M1811</guid>
      <dc:creator>GFN182</dc:creator>
      <dc:date>2021-09-22T19:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436001#M1812</link>
      <description>&lt;P&gt;One portal, two gateways&lt;/P&gt;&lt;P&gt;GW1. Regular users and caseA access to production, IP poolA&lt;/P&gt;&lt;P&gt;GW2. CaseB access to cyber, IP pool B&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using two gateways allows manual selection to which environment to connect, security rules for user group and subnetA OR subnetB allow access to one or the other&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For full segregation you could set up multiple virtual systems and host a gateway on each&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 20:30:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436001#M1812</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2021-09-22T20:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436024#M1813</link>
      <description>&lt;P&gt;Understood.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 22:30:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436024#M1813</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-22T22:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436883#M1831</link>
      <description>&lt;P&gt;this sounds possible, i will give it a shot&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 14:21:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436883#M1831</guid>
      <dc:creator>GFN182</dc:creator>
      <dc:date>2021-09-27T14:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436885#M1832</link>
      <description>&lt;P&gt;Working with my SE he recommended using a loopback interface on a different port. He demonstrated this in his lab.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Sep 2021 14:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/436885#M1832</guid>
      <dc:creator>GFN182</dc:creator>
      <dc:date>2021-09-27T14:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/461827#M2392</link>
      <description>&lt;P&gt;I have different purpose (new certificate with different CN) to create a new/parallel portal&amp;amp;gateway (to keep the change transparent for end user/and to keep easy revert back possibilities in worst case), so when i try to create a new por+gw by adding new pub-IP on same internet interface, using new certificate, using new client iP pool range,&amp;nbsp; i get below error while pushing the policy,&lt;/P&gt;&lt;P&gt;.&lt;STRONG&gt;&lt;EM&gt; SSLVPN: Invalid IPv4 pool value: xxxxxxxxxxxxxxxxxxx&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;. (Module: rasmgr)&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;. SSLVPN: failed to parse IP pool in tunnel xxxxxxxxxxx&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;. (Module: rasmgr)&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;. Parsing GlobalProtect gateway multi user configs failure&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;. (Module: rasmgr)&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;. Commit failed&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I checked multiple times that there is no overlapping of client subnet that i am using, and subnet value is also perfect, its large enough, tried with /24, /22, but still not sure why its giving above error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to configure two portal/gateway on same interface but with two different pub IPs and different tunnel interface and different client IP ranges ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 17:22:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/461827#M2392</guid>
      <dc:creator>IT.OPS</dc:creator>
      <dc:date>2022-01-28T17:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Portals/Gateways</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/461865#M2396</link>
      <description>&lt;P&gt;you can't use two ip's on the same interface. Use a loopback interface to achieve your goals.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jan 2022 21:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-portals-gateways/m-p/461865#M2396</guid>
      <dc:creator>GFN182</dc:creator>
      <dc:date>2022-01-28T21:57:18Z</dc:date>
    </item>
  </channel>
</rss>

