<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect External Gateways and Azure Traffic Manager - Potential configuration issues. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/447524#M2142</link>
    <description>&lt;P&gt;Hey mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we did actually. It turns out that using ATM was not the issue. For each of our external Gateways, we only ended up specifying itself as a gateway. As far as I know that means they aren't aware of the other External Gateways in our environment allowing ATM to handle the decision making effectively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When a client hits "&lt;SPAN&gt;vpn.organisation.com" in Azure Traffic Manager, it redirects the request to the relevant External Gateway (europe-vpn.organisation.com, australia1-vpn.organisation.com or&amp;nbsp;australia2-vpn.organisation.com) based on our selection criteria. We haven't had any issues with this so far and fail-over has been tested.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think when I posted this query I was having issues with the GP Client "Stealing Focus" and trying to find Gateways whilst on a corporate network..... That side of the issue was solved by enabling "Internal Host Detection". That enables the GP Client to figure out its on a corp/internal network and chill out.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Nov 2021 02:37:27 GMT</pubDate>
    <dc:creator>David_Godwin</dc:creator>
    <dc:date>2021-11-15T02:37:27Z</dc:date>
    <item>
      <title>Global Protect External Gateways and Azure Traffic Manager - Potential configuration issues.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/383582#M875</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We have been experiencing some odd behavior with our Global Protect Client VPN and I wanted to better understand what our design should look like and if we had conflict somewhere.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our organisation currently uses Azure Traffic Manager to distribute requests for vpn.organisation.com to geographically separated Palo Alto Gateways (based on a priority setting in azure rather than geo).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have 3 external gateways configured:&lt;/P&gt;&lt;P&gt;External Gateway 1 - europe-vpn.organisation.com&lt;BR /&gt;External Gateway 2 - australia1-vpn.organisation.com&lt;BR /&gt;External Gateway 3 - australia2-vpn.organisation.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been investigating the each of the 3 external gateways configuration and noticed the following:&lt;BR /&gt;GlobalProtect Portal Configuration --&amp;gt; Agent --&amp;gt; Configs&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Each site appears to have 2 x external gateways configured, for example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External Gateway 1&lt;BR /&gt;europe-vpn.organisation.com&lt;BR /&gt;vpn.organisation.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External Gateway 2&lt;BR /&gt;australia1-vpn.organisation.com&lt;BR /&gt;vpn.organisation.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External Gateway 3&lt;BR /&gt;australia2-vpn.organisation.com&lt;BR /&gt;vpn.organisation.com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ultimately my question is as follows:&lt;/P&gt;&lt;P&gt;Will using Azure Traffic Manager along with each External gateway having the configuration as described above, cause a conflict in the way that the gateways operate?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suspect that the individual external gateways 1/2/3 are using their own selection criteria and conflicting with what Azure Traffic Manager is doing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From some positive testing results, it looks like the external gateways 1/2/3 only need to have themselves configured so that the Azure Traffic Manager can do what it's supposed to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any advice, if I haven't explained clearly enough, please let me know.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 09:07:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/383582#M875</guid>
      <dc:creator>David_Godwin</dc:creator>
      <dc:date>2021-02-03T09:07:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect External Gateways and Azure Traffic Manager - Potential configuration issues.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/447051#M2132</link>
      <description>&lt;P&gt;Hi David,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you manage to resolve the issue? I have the same situation.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Nov 2021 17:49:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/447051#M2132</guid>
      <dc:creator>admin.mbashir</dc:creator>
      <dc:date>2021-11-11T17:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect External Gateways and Azure Traffic Manager - Potential configuration issues.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/447524#M2142</link>
      <description>&lt;P&gt;Hey mate,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes we did actually. It turns out that using ATM was not the issue. For each of our external Gateways, we only ended up specifying itself as a gateway. As far as I know that means they aren't aware of the other External Gateways in our environment allowing ATM to handle the decision making effectively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When a client hits "&lt;SPAN&gt;vpn.organisation.com" in Azure Traffic Manager, it redirects the request to the relevant External Gateway (europe-vpn.organisation.com, australia1-vpn.organisation.com or&amp;nbsp;australia2-vpn.organisation.com) based on our selection criteria. We haven't had any issues with this so far and fail-over has been tested.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I think when I posted this query I was having issues with the GP Client "Stealing Focus" and trying to find Gateways whilst on a corporate network..... That side of the issue was solved by enabling "Internal Host Detection". That enables the GP Client to figure out its on a corp/internal network and chill out.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 02:37:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/447524#M2142</guid>
      <dc:creator>David_Godwin</dc:creator>
      <dc:date>2021-11-15T02:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect External Gateways and Azure Traffic Manager - Potential configuration issues.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/1205525#M6407</link>
      <description>&lt;P&gt;Hi, I hope you're doing well. It's been almost four years now, and I just wanted to check in to see how you're managing the certificate for your GlobalProtect.&lt;/P&gt;
&lt;P&gt;We have a SAML certificate installed on every gateway, but pointing the main domin host to ATM caused some certificate errors for us.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 21:14:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-external-gateways-and-azure-traffic-manager/m-p/1205525#M6407</guid>
      <dc:creator>W.Principe183231</dc:creator>
      <dc:date>2025-01-27T21:14:34Z</dc:date>
    </item>
  </channel>
</rss>

