<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect client to access IPSEC peer networks. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/528883#M109200</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270265"&gt;@amar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This is easily accomplished when everything is actually in place and setup properly. A common thing I see people forget is the routing on the branch office side of things. You'll need a route on the BO so it actually knows it needs to send the GlobalProtect IPs back to the HO. What you're likely running into is the BO doesn't know where to send the GlobalProtect traffic once it's been received.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2023 14:44:23 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2023-01-27T14:44:23Z</dc:date>
    <item>
      <title>Global protect client to access IPSEC peer networks.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/528833#M109181</link>
      <description>&lt;P&gt;Hello - my query is that "Is it possible for Global protect client users of HO to access the resources located at branch office over IPSEC tunnel?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 3 branch locations configured Site to site IPSEC tunnels.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since I created a access rule in HO for the same but no success.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please suggest&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 07:49:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/528833#M109181</guid>
      <dc:creator>amar</dc:creator>
      <dc:date>2023-01-27T07:49:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect client to access IPSEC peer networks.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/528883#M109200</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270265"&gt;@amar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This is easily accomplished when everything is actually in place and setup properly. A common thing I see people forget is the routing on the branch office side of things. You'll need a route on the BO so it actually knows it needs to send the GlobalProtect IPs back to the HO. What you're likely running into is the BO doesn't know where to send the GlobalProtect traffic once it's been received.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 14:44:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/528883#M109200</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-01-27T14:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect client to access IPSEC peer networks.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/529017#M109223</link>
      <description>&lt;P&gt;Thank you so much&lt;/P&gt;
&lt;P&gt;I am sorry I forgot to mention the BO sites are CheckPoint devices and it supports policy-based VPN only. The GlobalProtect IP is configured in the VPN Policies as HO networks and is also allowed in Access rules bidirectionally.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Jan 2023 11:11:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/529017#M109223</guid>
      <dc:creator>amar</dc:creator>
      <dc:date>2023-01-28T11:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect client to access IPSEC peer networks.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/529307#M109271</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/270265"&gt;@amar&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It's been a long time since I've worked with Checkpoint in any real capacity (currently I'm more migrating people's configurations from CheckPoint to PAN), but I'd be verifying that the return traffic is actually hitting your HO firewall from the BO. If you aren't seeing the return traffic it's dying on the vine and you'll need to address the BO routing, but if it's making it back to the HO you have some other issue happening with routing or policy that you'll need to address on the HO side of things.&lt;/P&gt;
&lt;P&gt;So to start with I guess, are you seeing the return traffic make it back from the BO to the HO?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 14:48:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/529307#M109271</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-01-31T14:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect client to access IPSEC peer networks.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/529418#M109295</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, GlobalProtect IP object was missing at BO access policy. Just added and it worked.&lt;/P&gt;
&lt;P&gt;Thank you so much.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 06:55:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-client-to-access-ipsec-peer-networks/m-p/529418#M109295</guid>
      <dc:creator>amar</dc:creator>
      <dc:date>2023-02-01T06:55:01Z</dc:date>
    </item>
  </channel>
</rss>

