<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to have 2 portals and 2 gateways, each for different &amp;quot;VPN&amp;quot; connectivity and users? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possible-to-have-2-portals-and-2-gateways-each-for/m-p/1263698#M7528</link>
    <description>&lt;P&gt;Yes you can have multiple portals / gateways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can be accomplished either with NAT or second IP on WAN interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assuming you have more than 1 public IP then you can configure second IP with /32 mask.&lt;/P&gt;
&lt;P&gt;Let's say your WAN subnet is 1.1.1.0/24&lt;/P&gt;
&lt;P&gt;ISP GW IP is 1.1.1.1 and IP on your firewall 1.1.1.2/24&lt;/P&gt;
&lt;P&gt;Just add additional IP 1.1.1.3/32 on WAN interface and then you can assign this 1.1.1.3/32 to second portal/gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have only 1 WAN IP or if you have multiple ISPs then NAT comes handy (let us know if you prefer more details about NAT setup).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If auth method is the same then just keep 1 portal and assign different gateways to different users based on their AD group membership.&lt;/P&gt;</description>
    <pubDate>Sat, 05 Sep 2026 01:33:11 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2026-09-05T01:33:11Z</dc:date>
    <item>
      <title>Is it possible to have 2 portals and 2 gateways, each for different "VPN" connectivity and users?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possible-to-have-2-portals-and-2-gateways-each-for/m-p/1263685#M7522</link>
      <description>&lt;P&gt;Hi, hoping someone can guide me. I am trying to see if it's possible to have, basically, 2 VPN's on the same firewall. One portal/gateway would be for employees using radius/AD/DUO authentication and the new one would be for consultants. Same authentication methods although the consultants would be in a different AD group for auth/DUO. Basically, the goal is to employ HIP controls for anti-virus on the employee VPN but not on the consultant VPN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My thinking was to create a second portal and second gateway. I began looking at adding the portal but already have run into an issue. I choose the outside/untrust interface (it's the only public one) and want to select the ip address, there is nothing in the drop down list. I was thinking to use a different public NAT ip for the new portal, but there's nothing in the list at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So is this even possible and if so, how can I do it? Or is there a better way?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 17:01:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possible-to-have-2-portals-and-2-gateways-each-for/m-p/1263685#M7522</guid>
      <dc:creator>Jpergolizzi</dc:creator>
      <dc:date>2026-09-04T17:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to have 2 portals and 2 gateways, each for different "VPN" connectivity and users?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possible-to-have-2-portals-and-2-gateways-each-for/m-p/1263698#M7528</link>
      <description>&lt;P&gt;Yes you can have multiple portals / gateways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can be accomplished either with NAT or second IP on WAN interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assuming you have more than 1 public IP then you can configure second IP with /32 mask.&lt;/P&gt;
&lt;P&gt;Let's say your WAN subnet is 1.1.1.0/24&lt;/P&gt;
&lt;P&gt;ISP GW IP is 1.1.1.1 and IP on your firewall 1.1.1.2/24&lt;/P&gt;
&lt;P&gt;Just add additional IP 1.1.1.3/32 on WAN interface and then you can assign this 1.1.1.3/32 to second portal/gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have only 1 WAN IP or if you have multiple ISPs then NAT comes handy (let us know if you prefer more details about NAT setup).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If auth method is the same then just keep 1 portal and assign different gateways to different users based on their AD group membership.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2026 01:33:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/is-it-possible-to-have-2-portals-and-2-gateways-each-for/m-p/1263698#M7528</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2026-09-05T01:33:11Z</dc:date>
    </item>
  </channel>
</rss>

