<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect: Using an alternative port in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-using-an-alternative-port/m-p/520138#M3396</link>
    <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Good morning.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;BR /&gt;I require a bit of assistance for deploying GlobalProtect with a twist.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;A client of ours wishes to deploy Global Protect but unfortunately, they also have a Web Facing application using SSL on the same ISP interface.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;This is unfortunately causing issues since GP also makes use of 443(SSL) and due to the DNAT rule in place for this web app, any traffic originating with application SSL is being natted to the internal web-app server.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;I did some research and found implemented the following:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGKCA0#:~:text=Although%20it%20is%20not%20possible,IP%20address%20and%20security%20rules." target="_blank"&gt;How to Configure GlobalProtect Portal Page to be Accessed on an... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;But this did not resolve the SSL issue.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Therefore, it seems that there can only be either a DNAT that will point SSL traffic to the loopback of the global protect or a DNAT that will point SSL traffic to the web-app server.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;One alternative is making use of the alternative ISP link but the client does not wish to go down that route for the time being.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;I hope I have provided enough information. &lt;BR /&gt;&lt;BR /&gt;Any ideas would be appreciated. &lt;BR /&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 03 Nov 2022 10:42:56 GMT</pubDate>
    <dc:creator>MGiusti</dc:creator>
    <dc:date>2022-11-03T10:42:56Z</dc:date>
    <item>
      <title>GlobalProtect: Using an alternative port</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-using-an-alternative-port/m-p/520138#M3396</link>
      <description>&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Good morning.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&lt;BR /&gt;I require a bit of assistance for deploying GlobalProtect with a twist.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;A client of ours wishes to deploy Global Protect but unfortunately, they also have a Web Facing application using SSL on the same ISP interface.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;This is unfortunately causing issues since GP also makes use of 443(SSL) and due to the DNAT rule in place for this web app, any traffic originating with application SSL is being natted to the internal web-app server.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;I did some research and found implemented the following:&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGKCA0#:~:text=Although%20it%20is%20not%20possible,IP%20address%20and%20security%20rules." target="_blank"&gt;How to Configure GlobalProtect Portal Page to be Accessed on an... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;But this did not resolve the SSL issue.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;Therefore, it seems that there can only be either a DNAT that will point SSL traffic to the loopback of the global protect or a DNAT that will point SSL traffic to the web-app server.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;One alternative is making use of the alternative ISP link but the client does not wish to go down that route for the time being.&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 11.0pt;"&gt;I hope I have provided enough information. &lt;BR /&gt;&lt;BR /&gt;Any ideas would be appreciated. &lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2022 10:42:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-using-an-alternative-port/m-p/520138#M3396</guid>
      <dc:creator>MGiusti</dc:creator>
      <dc:date>2022-11-03T10:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect: Using an alternative port</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-using-an-alternative-port/m-p/520589#M3407</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/204575"&gt;@MGiusti&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Your DNAT statement for GlobalProtect wouldn't be using tcp/443 when you change the port of the portal/gateway, it'll be using whatever port you've selected that isn't already being used for your web server. How exactly are you attempting to set up your NAT statements? Sounds like something that you're setting there isn't being done properly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 01:38:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-using-an-alternative-port/m-p/520589#M3407</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-11-08T01:38:20Z</dc:date>
    </item>
  </channel>
</rss>

