<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Behind NAT in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-behind-nat/m-p/517962#M3296</link>
    <description>&lt;P&gt;I have a PA-800 with global protect configured in an internal network. A 1to1 NAT has been setup to map a public IP address to the internal IP address of the external interface of the PA. The &lt;SPAN&gt;1to1 NAT is on a Cisco ASA5508X with direct passthrough on 443. &lt;/SPAN&gt;I set the same internal IP address on the portal and the gateway. When authenticating from the internet, I get to the portal and enter my credentials, it then pushes down a gateway address which is the internal IP address and for obvious reasons fails to setup the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought the solution would be to connect to the PA from a host in the internal network which can access that internal IP, and via the management interface, change the gateway local IP, from the internal IP address to the public IP address. However, when I try to change the gateway IP from the internal IP to the public IP it fails to allow me to change that setting. Is this because I've connected via global protect to make this config change? Could there be any other reason I can't change the local IP on the gateway?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for any help.&lt;/P&gt;</description>
    <pubDate>Fri, 14 Oct 2022 15:35:39 GMT</pubDate>
    <dc:creator>chris_brighton</dc:creator>
    <dc:date>2022-10-14T15:35:39Z</dc:date>
    <item>
      <title>Global Protect Behind NAT</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-behind-nat/m-p/517962#M3296</link>
      <description>&lt;P&gt;I have a PA-800 with global protect configured in an internal network. A 1to1 NAT has been setup to map a public IP address to the internal IP address of the external interface of the PA. The &lt;SPAN&gt;1to1 NAT is on a Cisco ASA5508X with direct passthrough on 443. &lt;/SPAN&gt;I set the same internal IP address on the portal and the gateway. When authenticating from the internet, I get to the portal and enter my credentials, it then pushes down a gateway address which is the internal IP address and for obvious reasons fails to setup the tunnel.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought the solution would be to connect to the PA from a host in the internal network which can access that internal IP, and via the management interface, change the gateway local IP, from the internal IP address to the public IP address. However, when I try to change the gateway IP from the internal IP to the public IP it fails to allow me to change that setting. Is this because I've connected via global protect to make this config change? Could there be any other reason I can't change the local IP on the gateway?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for any help.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 15:35:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-behind-nat/m-p/517962#M3296</guid>
      <dc:creator>chris_brighton</dc:creator>
      <dc:date>2022-10-14T15:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Behind NAT</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-behind-nat/m-p/518909#M3358</link>
      <description>&lt;P&gt;Found the solution. The external gateway in the client configuration of the global protect portal was the part that needed to have a public IP. See the following article; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKHCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKHCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 13:42:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-behind-nat/m-p/518909#M3358</guid>
      <dc:creator>chris_brighton</dc:creator>
      <dc:date>2022-10-24T13:42:54Z</dc:date>
    </item>
  </channel>
</rss>

