<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Gateway behind reverse proxy in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-gateway-behind-reverse-proxy/m-p/1252444#M7344</link>
    <description>&lt;P&gt;Is there a way to put the globalprotect gateway behind a reverse proxy for sslvpn only?&lt;BR /&gt;I know that technically you can just NAT to the gateway but it is wanted to put the gateway behind a reverse proxy and not use ipsec, only sslvpn.&lt;BR /&gt;When I try this, the globalprotect app is allowed but the connection fails nonetheless. I assume this is because the reverse proxy is basically breaking open the connection and in this case is the "meddler in the middle" and is simply not possible because of this?!?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Apr 2026 15:30:42 GMT</pubDate>
    <dc:creator>CLiqr</dc:creator>
    <dc:date>2026-04-17T15:30:42Z</dc:date>
    <item>
      <title>GlobalProtect Gateway behind reverse proxy</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-gateway-behind-reverse-proxy/m-p/1252444#M7344</link>
      <description>&lt;P&gt;Is there a way to put the globalprotect gateway behind a reverse proxy for sslvpn only?&lt;BR /&gt;I know that technically you can just NAT to the gateway but it is wanted to put the gateway behind a reverse proxy and not use ipsec, only sslvpn.&lt;BR /&gt;When I try this, the globalprotect app is allowed but the connection fails nonetheless. I assume this is because the reverse proxy is basically breaking open the connection and in this case is the "meddler in the middle" and is simply not possible because of this?!?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2026 15:30:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-gateway-behind-reverse-proxy/m-p/1252444#M7344</guid>
      <dc:creator>CLiqr</dc:creator>
      <dc:date>2026-04-17T15:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway behind reverse proxy</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-gateway-behind-reverse-proxy/m-p/1252524#M7345</link>
      <description>&lt;P&gt;Is the intent to disable IPSec in favor of SSL, because you can simply set that in the GlobalProtect gateway:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_1-1776674522461.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71271i3E30F7762BE7E0C0/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_1-1776674522461.png" alt="reaper_1-1776674522461.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like your reverse proxy may be changing things in the payload of the TLS connection, could it be set to passthrough and not interfere/decrypt ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 08:44:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-gateway-behind-reverse-proxy/m-p/1252524#M7345</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-04-20T08:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway behind reverse proxy</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-gateway-behind-reverse-proxy/m-p/1252531#M7346</link>
      <description>&lt;P&gt;intent is to allow globalprotect through port 443 as sslvpn in most guest or public networks is not blocked but there is no separate IP&lt;BR /&gt;problem is that a reverse proxy is already in place on the only IP&lt;BR /&gt;configuring the proxy as stream proxy and then forwarding all but that one SNI to another loopback IP address of the reverse proxy is unfortunately not an option and it seems there is no other option globalprotect likely intentionally doesnt not establish the tunnel if this is detected&lt;/P&gt;</description>
      <pubDate>Mon, 20 Apr 2026 09:47:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-gateway-behind-reverse-proxy/m-p/1252531#M7346</guid>
      <dc:creator>CLiqr</dc:creator>
      <dc:date>2026-04-20T09:47:28Z</dc:date>
    </item>
  </channel>
</rss>

