<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Gateways needed due to SAML in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-gateways-needed-due-to-saml/m-p/463207#M2427</link>
    <description>&lt;P&gt;Hi, I have been looking for the same answer, by enabling SAML on the vpn you end up loosing functionality and you must have a mix of SAML and AD groups to keep being able to segment the VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been browsing the community and found that you can possibly configure different gateways using loopback addresses, however no documentation I have found. After many tests and tries i was finally able to configure different gateways using NAT. However they only work with SSL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you wish to segment admin users from regular users without AD groups, this might be a good solution, since admin users do not require much bandwidth for admin related tasks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
    <pubDate>Fri, 02 Sep 2022 12:58:16 GMT</pubDate>
    <dc:creator>GnContente</dc:creator>
    <dc:date>2022-09-02T12:58:16Z</dc:date>
    <item>
      <title>Multiple Gateways needed due to SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-gateways-needed-due-to-saml/m-p/353667#M464</link>
      <description>&lt;P&gt;Hello folks!&lt;BR /&gt;&lt;BR /&gt;Whenever this question is posed, the response is always a question: "Why do you want multiple gateways on the same firewall?".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Customer wants to use SAML Idp (Azure MFA) which is fine unless you need a fallback authentication profile since SAML is not supported in an Authentication Sequence. The customer also insists that contractors (me) use a locally defined account. Since I can't define a sequence to accomplish this I was wondering if anyone knows if multiple gateways behind one IP are finally supported. One for SAML, one for everything else, with different levels of access in policy.&lt;BR /&gt;&lt;BR /&gt;Other vendors seems to support this functionality but that's not really an answer...&lt;BR /&gt;&lt;BR /&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 20:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-gateways-needed-due-to-saml/m-p/353667#M464</guid>
      <dc:creator>Lutzor</dc:creator>
      <dc:date>2020-10-02T20:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Gateways needed due to SAML</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-gateways-needed-due-to-saml/m-p/463207#M2427</link>
      <description>&lt;P&gt;Hi, I have been looking for the same answer, by enabling SAML on the vpn you end up loosing functionality and you must have a mix of SAML and AD groups to keep being able to segment the VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been browsing the community and found that you can possibly configure different gateways using loopback addresses, however no documentation I have found. After many tests and tries i was finally able to configure different gateways using NAT. However they only work with SSL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you wish to segment admin users from regular users without AD groups, this might be a good solution, since admin users do not require much bandwidth for admin related tasks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2022 12:58:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/multiple-gateways-needed-due-to-saml/m-p/463207#M2427</guid>
      <dc:creator>GnContente</dc:creator>
      <dc:date>2022-09-02T12:58:16Z</dc:date>
    </item>
  </channel>
</rss>

