<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect mixed internal and external gateway in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/469859#M2525</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184036"&gt;@Land-Salzburg&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This document describes almost exactly what you are trying to do -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me highlight the main points:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Only 1 portal is needed.&amp;nbsp; It is a separate appliance in the diagram, but all portals and gateways can be on a single NGFW.&lt;/LI&gt;&lt;LI&gt;Two gateways are used, internal and external.&lt;/LI&gt;&lt;LI&gt;The client uses Internal Host Detection to determine whether to connect to the internal or external gateway (2nd sentence).&lt;/LI&gt;&lt;LI&gt;The 1st note block says that the internal connections can be always-on while the external gateway can be on-demand.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;You can have the portal and internal gateway authenticate with LDAP and the external gateway authenticates via RADIUS w/MFA.&amp;nbsp; Assuming that the LDAP and RADIUS user/pass is the same, the authentication should be seamless with 1 MFA prompt for the external gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 02 Mar 2022 18:05:53 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2022-03-02T18:05:53Z</dc:date>
    <item>
      <title>Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/469674#M2519</link>
      <description>&lt;P&gt;hi everybody, i've some questions regarding global protect client and mixed environment internal / external&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a internal campus networking infrastructure with lan and wlan (2 different subnets), so the laptop changes the ip-address if traveling around the campus, wired or unwired...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so we have installed global protect client for internal use without tunnel mode for user-id through palo firewall for internet access...this seems to work..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but now:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; users want to connect with global protect from external to campus network, external access is planed with multi-factor-auth&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; via radius config in global protect&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now i've tried several things:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 portal-config setups (internal and external) because we need 2 different connect methods for global protect&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;on demand with mfa via radius-auth (if user connects external)&lt;/LI&gt;&lt;LI&gt;always on with ldap-auth (if user is on campus network)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;and 2 gateway-config setups&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;tunnel mode (if user connects external)&lt;/LI&gt;&lt;LI&gt;no mode (if user is on campus network)&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this setup recommended?&lt;/P&gt;&lt;P&gt;or what would be best practise?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; 1 portal and mfa internal + external?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i've seen some strange behaviour with mixed portal config...sometimes client does not connect internal when last connection was external...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe someone can help me....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards, fabian&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 07:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/469674#M2519</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-03-02T07:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/469859#M2525</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184036"&gt;@Land-Salzburg&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This document describes almost exactly what you are trying to do -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me highlight the main points:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Only 1 portal is needed.&amp;nbsp; It is a separate appliance in the diagram, but all portals and gateways can be on a single NGFW.&lt;/LI&gt;&lt;LI&gt;Two gateways are used, internal and external.&lt;/LI&gt;&lt;LI&gt;The client uses Internal Host Detection to determine whether to connect to the internal or external gateway (2nd sentence).&lt;/LI&gt;&lt;LI&gt;The 1st note block says that the internal connections can be always-on while the external gateway can be on-demand.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;You can have the portal and internal gateway authenticate with LDAP and the external gateway authenticates via RADIUS w/MFA.&amp;nbsp; Assuming that the LDAP and RADIUS user/pass is the same, the authentication should be seamless with 1 MFA prompt for the external gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 18:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/469859#M2525</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-03-02T18:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470063#M2528</link>
      <description>&lt;P&gt;hi tom, thanks for your answers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i've already seen this diagramm / howto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nevertheless: i've some more questions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;one ngfw and i've made one portal:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;first question: my dns-records (internal and official / external)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; should these be the same fqdn?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;vpn.abc.com&amp;nbsp; (resolves to external official ip if laptop is out of campus)&lt;/LI&gt;&lt;LI&gt;vpn.abc.com&amp;nbsp; (resolves to internal private ip if laptop is onsite)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;next question: different agent config on portal configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;network -- global protect -- portals -- myportal&lt;UL&gt;&lt;LI&gt;tab agent &amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;UL&gt;&lt;LI&gt;do i insert 2 agent configs and how do they differ ? where to set host detection and where not?&lt;/LI&gt;&lt;LI&gt;where to set internal gw / external gw and where not?&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;i've made a screenshot of current portal config..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schule.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39421iDB4E3D8EC4B51DDC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="schule.JPG" alt="schule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with this single portal config the gp-client internal says: global protect portal does not exists...so i need 2 portals or not?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the gateways are here:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="schule-intern.JPG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/39422i459203497D23713A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="schule-intern.JPG" alt="schule-intern.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;radius and ldap-server use same user-credentials, radius was only configured for mfa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;maybe you can give me some advice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards, fabian&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 17:13:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470063#M2528</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-03-03T17:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470342#M2532</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184036"&gt;@Land-Salzburg&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The DNS records should be the same.&amp;nbsp; Both should resolve to the public IP of the portal.&amp;nbsp; The portal is configured for that IP address only, otherwise you will get the "portal does not exist" error.&lt;/LI&gt;&lt;LI&gt;The portal agent configuration should be always-on.&amp;nbsp; Under the Network &amp;gt; GlobalProtect &amp;gt; Portals &amp;gt; &amp;lt;portal-config&amp;gt; &amp;gt; Agent &amp;gt; &amp;lt;agent-config&amp;gt; &amp;gt; External tab, change the priority of your gateway to "Manual only".&amp;nbsp; The doc does not tell you how to do this.&amp;nbsp; This prevents the client from automatically connecting to the external gateway.&lt;/LI&gt;&lt;LI&gt;Internal Host Detection is setup under the Network &amp;gt; GlobalProtect &amp;gt; Portals &amp;gt; &amp;lt;portal-config&amp;gt; &amp;gt; Agent &amp;gt; &amp;lt;agent-config&amp;gt; &amp;gt; Internal tab.&amp;nbsp; You can click the ? button in the upper right of the box for instructions.&lt;/LI&gt;&lt;LI&gt;The doc uses different DNS names for the 2 gateways.&amp;nbsp; That is a good idea.&amp;nbsp; The external gateway is configured on the external IP address, and the internal gateway is configured on the internal IP address.&amp;nbsp; The DNS records should match what you configure in the portal.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I think I answered all of your questions.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 00:00:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470342#M2532</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-03-04T00:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470431#M2535</link>
      <description>&lt;P&gt;hi tom, thanks for your answers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so i set 2 agent-configs on the portal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;agent-conf-external&amp;nbsp; -- with option internal host detection, set ip addresses for internal and external gateway and method "on-demand"&lt;/LI&gt;&lt;LI&gt;agent-conf-internal -- with option internal host detection, set ip addresses for internal and external gateway and method "always-on"&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;i've also made 2 gateways internal and external&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;gw-external -- with mfa-auth and tunnel mode&lt;/LI&gt;&lt;LI&gt;gw-internal -- with ldap and NO tunnel setting&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now an interesting thing:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;laptop onsite of campus: global-protect-client connects to portal, enter credentials and after that enables and establish and ipsec-tunnel...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and some other problem: radius-auth on gateway without radius-auth on portal does not work, agent keeps disconnected...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it seems the gp-agent does not recognize internal use...how can i debug this? what could be possible wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards, fabian&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 14:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470431#M2535</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-03-04T14:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470549#M2539</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184036"&gt;@Land-Salzburg&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You need to use &lt;EM&gt;one&lt;/EM&gt; GP portal agent config with both the internal and external gateways configured, and the priority of the external gateway should be "Manual only".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your GP client is always selecting the external gateway because you configured it to do so with the 1st agent config.&amp;nbsp; Multiple agent configs only work if the OS and/or users are different.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regard to mixed authentication methods for the portal and gateway, I have done that before.&amp;nbsp; What version of PAN-OS do you have?&amp;nbsp; What is your disconnect message?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 15:04:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470549#M2539</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-03-04T15:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470585#M2540</link>
      <description>&lt;P&gt;hi tom,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your support....I'm not inconveniencing you, I hope, seems a difficult topic to me...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;well maybe my mistake: i thought it needs 2 agent configs on the single-portal,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1st config for internal always-on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; and&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2nd config for external on-demand&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'll change the single-portal --&amp;gt; agent config to 1 config with internal and external gateways set and internal host&amp;nbsp; detection activated..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i wasn't aware of the the function portal-config --&amp;gt; agent-config --&amp;gt; external gateway --&amp;gt; source region any and priority manual setting&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mfa-topic:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;current pan-os: 10.1.2&lt;/P&gt;&lt;P&gt;current gpa: 5.2.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;behaviour: agent connects --&amp;gt; enter user and pwd --&amp;gt; enter pin-code --&amp;gt; nothing happens....agent keeps trying to connect, but no&lt;/P&gt;&lt;P&gt;logging even in the agent-debug log....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;strange...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards, fabian&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 15:53:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470585#M2540</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-03-04T15:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470586#M2541</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/184036"&gt;@Land-Salzburg&lt;/a&gt; !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do the logs say on the MFA side?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 15:57:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470586#M2541</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2022-03-04T15:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470593#M2542</link>
      <description>&lt;P&gt;hi tom,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i can deliver the logs on monday, out of office now..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards, fabian&lt;/P&gt;</description>
      <pubDate>Fri, 04 Mar 2022 16:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/470593#M2542</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-03-04T16:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect mixed internal and external gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/472479#M2564</link>
      <description>&lt;P&gt;for those who have the same problem:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;portal with 2fa and gateway with 2fa:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if using panos 10.1.2 &amp;gt;&amp;gt; pls upgrade&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;PAN-177119&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Fixed an issue with the GlobalProtect gateway where SMS-message-based multi-factor authentication (MFA) did not display a prompt to enter the authentication code.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;that fixed my radius-troubles on gateway authentication&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 21:04:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-mixed-internal-and-external-gateway/m-p/472479#M2564</guid>
      <dc:creator>Land-Salzburg</dc:creator>
      <dc:date>2022-03-11T21:04:13Z</dc:date>
    </item>
  </channel>
</rss>

