<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Get a defined target IP Adress and Subnet via GlobalProtect (PA-460) in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580410#M5127</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;thanks a lot for your answer. I'm not using an AD but local users I configured in the local user database in this setup, so I'm afraid that &lt;SPAN&gt;"Retrieve Framed-IP-Address attribute from authentication server"&lt;/SPAN&gt; might not help fixing my issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meanwhile I found this method to be able to receive a static IP address with my client pc which seems to work:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIMCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIMCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My ethernet configuration still shows me I have a subnet mask of 255.255.255.255 configured and I still cannot reach the target machine. From my understanding a matching subnet mask of both communicating machines is obligatory so they're able to find themselves via ARP broadcasting.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-14 163711.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58320i4DCAA24D20A1A2FA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-03-14 163711.png" alt="Screenshot 2024-03-14 163711.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;So how's it possible to configure a matching subnet mask of 255.255.255.0?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Sascha&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2024 15:38:37 GMT</pubDate>
    <dc:creator>SaArlt</dc:creator>
    <dc:date>2024-03-14T15:38:37Z</dc:date>
    <item>
      <title>Get a defined target IP Adress and Subnet via GlobalProtect (PA-460)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580087#M5118</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;I have a target system that I need to access via WebUI. The system is reachable via its IP address 192.168.255.129 with a /24 (255.255.255.0) subnet. Furthermore the system expects a client IP address of 192.168.255.130, any other IP address will be rejected. The target system is a "proprietary blackbox", which means these settings cannot be changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any locally connected client can reach the target system via the above mentioned IP settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My objective is to reach this system now via a GlobalProtect VPN connection, so I set the DHCP IP pool of the gateway configuration to the target systems network (192.168.255.0/24) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bild (3).png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58248i02BF08180E06445A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Bild (3).png" alt="Bild (3).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;I wasn't able reach the target system, yet.&lt;/P&gt;
&lt;P&gt;I'm facing different issues, here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;I set the IP pool to 192.168.255.0/24 for the needed 255.255.255.0 subnet mask. However, if I look into the network settings, I have a subnet of 255.255.255.255 configured for the virtual adapter. Shouldn't this be the expected 255.255.255.0 subnet?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bild (2).png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58247i73FEC44D4F611B5F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Bild (2).png" alt="Bild (2).png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&amp;nbsp;How can I force my client to use the 192.168.255.130 address? I couldn't come up with an idea, yet. If I set the DHCP range to 192.168.255.130-192.168.255.131 for instance as I need the /24 subnet which is not possible to configure when defining a range like this.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot in advance for your help&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 16:34:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580087#M5118</guid>
      <dc:creator>SaArlt</dc:creator>
      <dc:date>2024-03-12T16:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Get a defined target IP Adress and Subnet via GlobalProtect (PA-460)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580204#M5122</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1433441729"&gt;@SaArlt&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the option "Retrieve Framed-IP-Address attribute from authentication server" you can assign a fixed IP address to GP users with AD (LDAP) Authentication.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check if the following article can help you:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UkxCAE&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_blank" rel="noopener"&gt;How to Assign a Fixed IP address to GlobalProtect Users with Active Directory (LDAP) Authentication using the Framed-IP-Address attribute.&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;Kim.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 11:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580204#M5122</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-03-13T11:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: Get a defined target IP Adress and Subnet via GlobalProtect (PA-460)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580410#M5127</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;thanks a lot for your answer. I'm not using an AD but local users I configured in the local user database in this setup, so I'm afraid that &lt;SPAN&gt;"Retrieve Framed-IP-Address attribute from authentication server"&lt;/SPAN&gt; might not help fixing my issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Meanwhile I found this method to be able to receive a static IP address with my client pc which seems to work:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIMCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIMCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My ethernet configuration still shows me I have a subnet mask of 255.255.255.255 configured and I still cannot reach the target machine. From my understanding a matching subnet mask of both communicating machines is obligatory so they're able to find themselves via ARP broadcasting.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-14 163711.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58320i4DCAA24D20A1A2FA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-03-14 163711.png" alt="Screenshot 2024-03-14 163711.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;So how's it possible to configure a matching subnet mask of 255.255.255.0?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Sascha&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 15:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580410#M5127</guid>
      <dc:creator>SaArlt</dc:creator>
      <dc:date>2024-03-14T15:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Get a defined target IP Adress and Subnet via GlobalProtect (PA-460)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580756#M5148</link>
      <description>&lt;P&gt;Any ideas here?&lt;/P&gt;
&lt;P&gt;Any help would be highly appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks a lot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards,&lt;/P&gt;
&lt;P&gt;Sascha&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 09:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580756#M5148</guid>
      <dc:creator>SaArlt</dc:creator>
      <dc:date>2024-03-18T09:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Get a defined target IP Adress and Subnet via GlobalProtect (PA-460)</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580797#M5151</link>
      <description>&lt;P&gt;this is a remote user VPN connection, you will not get a /24 subnetmask as you're behind a VPN tunnel and this is your local IP (assigning a /24 would make that a locally connected network)&lt;/P&gt;
&lt;P&gt;Furthermore you shouldn't share the same subnet on a physical interface and the GP pool as that will inevitably introduce routing issues (these are 2 different 'networks')&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;that said, if the proprietary blackbox needs to be reached from a system in it's own subnet, I propose you set up NAT that masks GP users behind the dataplane interface IP of the interface connecting to the black box&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;e.g&lt;/P&gt;
&lt;P&gt;GP IP pool 10.0.0.0/24&lt;/P&gt;
&lt;P&gt;dataplane interface&amp;nbsp;&lt;SPAN&gt;192.168.255.130/24&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;NAT rule from 10.0.0.0/24 to&amp;nbsp;192.168.255.129 source NAT&amp;nbsp;192.168.255.130&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;that should fiox your issue&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 14:07:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/get-a-defined-target-ip-adress-and-subnet-via-globalprotect-pa/m-p/580797#M5151</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-03-18T14:07:26Z</dc:date>
    </item>
  </channel>
</rss>

