<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Setup in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237121#M6995</link>
    <description>&lt;P&gt;BUT each gateway requires separate external IP/URL and interface correct?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Sep 2025 17:32:59 GMT</pubDate>
    <dc:creator>S_Williams901</dc:creator>
    <dc:date>2025-09-02T17:32:59Z</dc:date>
    <item>
      <title>Global Protect Setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237109#M6993</link>
      <description>&lt;P&gt;Trying to setup GP for a scenario. One large org, multiple entities/departments that will require different policies, HIP checks, some will be manual connection, some will be always on.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The requirements that we would like to have are:&lt;BR /&gt;&lt;BR /&gt;1 URL for all users to type in a browser to download client if need be, and same URL to be the entry for their client.&lt;BR /&gt;&lt;BR /&gt;I have tried one portal and one gateway with multiple agent configs but the HIP checks are the blockers as it seems you cannot have HIP check messages per agent config or per AD user group.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;How are others achieving this?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We do not want endpoints that are different, for example, &lt;A href="mailto:dept1@domai.com," target="_blank"&gt;dept1@domain.com, dept2@domain.com&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;for the GP gateways.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 14:35:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237109#M6993</guid>
      <dc:creator>S_Williams901</dc:creator>
      <dc:date>2025-09-02T14:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237116#M6994</link>
      <description>&lt;P&gt;You can have 1 portal (so 1 URL / portal address to access).&lt;/P&gt;
&lt;P&gt;Different gateway configs are given to users in different AD groups.&lt;/P&gt;
&lt;P&gt;Different gateways present different HIP notifications to users.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 16:45:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237116#M6994</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-09-02T16:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237121#M6995</link>
      <description>&lt;P&gt;BUT each gateway requires separate external IP/URL and interface correct?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 17:32:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237121#M6995</guid>
      <dc:creator>S_Williams901</dc:creator>
      <dc:date>2025-09-02T17:32:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Setup</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237221#M7000</link>
      <description>&lt;P&gt;Ideally yes.&lt;/P&gt;
&lt;P&gt;It is also possible to run them on different internal interfaces.&lt;/P&gt;
&lt;P&gt;Different external ports dnatted to different internal gateway IPs like example below.&lt;/P&gt;
&lt;P&gt;vpn.mycompany.com:6443 &amp;gt; 10.0.0.1:443&lt;/P&gt;
&lt;P&gt;vpn.mycompany.com:7443 &amp;gt; 10.0.1.1:443&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Issue is that then you can probably do SSL-VPN only (more overhead, more sensitive to packet loss) as I am not aware capability to run IPSec (UDP/4501) on alternate port externally.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 15:42:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-setup/m-p/1237221#M7000</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-09-03T15:42:37Z</dc:date>
    </item>
  </channel>
</rss>

