<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Global Protect gateways on same firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/541312#M110964</link>
    <description>&lt;P&gt;I know this post is fairly old, but thank you for this!!&amp;nbsp; This was such a simple yet brilliant solution to overcome Palo Alto's terrible failure to track which interface a packet came in and should exit out of.&amp;nbsp; This is also the only solution I was able to find that you can concurrently use both gateways on the same firewall over each ISP.&amp;nbsp; Even better, this doesn't require loopback interfaces, NAT'ing, PBF rules, or even any sort of manual intervention when a failure occurs.&lt;/P&gt;</description>
    <pubDate>Sat, 06 May 2023 02:59:30 GMT</pubDate>
    <dc:creator>NickAssar</dc:creator>
    <dc:date>2023-05-06T02:59:30Z</dc:date>
    <item>
      <title>Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67166#M39445</link>
      <description>&lt;P&gt;I have a PA-3020 that will have two ISP connections. Primary ISP interface will be used for the Global Protect Portal and Primary Gateway using tunnel.1. Is it possible to have a second gateway using tunnel.2 on the same firewall using the secondary ISP interface?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, if the Portal is only on the primary ISP interface and that connection is down making the Portal unreachable, will the GP Client still connect to the secondary Gateway?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 20:52:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67166#M39445</guid>
      <dc:creator>Nathan.McCart</dc:creator>
      <dc:date>2015-10-22T20:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67170#M39446</link>
      <description>&lt;P&gt;Yes you can have multiple gateways.&lt;/P&gt;
&lt;P&gt;Just run it on interface of diferent isp connection.&lt;/P&gt;
&lt;P&gt;Clients should cache gateway information they get from portal so even if portal is down they try to connect to gateways they have in their cache.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 21:05:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67170#M39446</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-22T21:05:40Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67171#M39447</link>
      <description>&lt;P&gt;I know I have used the following to help me out in the past. It should be possible, but its gonna task some whiteboarding to making it work properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-a-Palo-Alto-Networks-Firewall-with-Dual-ISPs/ta-p/59774&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps...&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 21:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67171#M39447</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-10-22T21:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67182#M39452</link>
      <description>&lt;P&gt;I was going to use PBF rules to manage the traffic. Would it be better to have two VRs to handle each ISP routing table?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Oct 2015 23:26:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67182#M39452</guid>
      <dc:creator>Nathan.McCart</dc:creator>
      <dc:date>2015-10-22T23:26:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67208#M39463</link>
      <description>&lt;P&gt;You can use just one, especially if you are using dynamic routing such as OSPF (I have had issues with this in the past without using physical interfaces. There are documents out there that show how to do this with one VR.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2015 13:42:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67208#M39463</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-10-23T13:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67456#M39534</link>
      <description>&lt;P&gt;I ended up using two virtual routers and it was fine. The ISPs are set up as active/passive so the second gateway is used when the primary gateway is down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 15:59:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/67456#M39534</guid>
      <dc:creator>Nathan.McCart</dc:creator>
      <dc:date>2015-10-29T15:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/317178#M81527</link>
      <description>&lt;P&gt;but how do you reach the internal if on the interface like lan you can only connect one VR? how do you route the traffic&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 10:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/317178#M81527</guid>
      <dc:creator>Matteo</dc:creator>
      <dc:date>2020-03-19T10:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/318170#M81720</link>
      <description>&lt;P&gt;same problem here...&amp;nbsp;&lt;SPAN&gt;how do you route the traffic to the internal lan?&lt;BR /&gt;thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 09:37:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/318170#M81720</guid>
      <dc:creator>mariocutroneo</dc:creator>
      <dc:date>2020-03-24T09:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/323477#M82645</link>
      <description>&lt;P&gt;You have to add the routes of course from one VR to the other, using inter VR routes.&lt;/P&gt;&lt;P&gt;I have it working: even when ISP1 is up, I can connect to both gateways (ISP1 in VR1, ISP2 in VR2) and I can always reach my LAN 192.168.1.0/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN resides in VR1&lt;/P&gt;&lt;P&gt;In VR1 I route the pool of Globalprotect gateway-ISP2 to VR2&lt;/P&gt;&lt;P&gt;In VR2 I route 192.168.1.0/24 to VR1&lt;/P&gt;</description>
      <pubDate>Fri, 17 Apr 2020 19:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/323477#M82645</guid>
      <dc:creator>StevenEerdekens</dc:creator>
      <dc:date>2020-04-17T19:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/389222#M90605</link>
      <description>&lt;P&gt;Just to let everyone know that a Blog has been written about this subject here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/blogs/multiple-globalprotect-portals-and-gateways/ba-p/360452" target="_blank"&gt;https://live.paloaltonetworks.com/t5/blogs/multiple-globalprotect-portals-and-gateways/ba-p/360452&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please be sure to check it out.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 21:41:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/389222#M90605</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2021-03-04T21:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Global Protect gateways on same firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/541312#M110964</link>
      <description>&lt;P&gt;I know this post is fairly old, but thank you for this!!&amp;nbsp; This was such a simple yet brilliant solution to overcome Palo Alto's terrible failure to track which interface a packet came in and should exit out of.&amp;nbsp; This is also the only solution I was able to find that you can concurrently use both gateways on the same firewall over each ISP.&amp;nbsp; Even better, this doesn't require loopback interfaces, NAT'ing, PBF rules, or even any sort of manual intervention when a failure occurs.&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 02:59:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-global-protect-gateways-on-same-firewall/m-p/541312#M110964</guid>
      <dc:creator>NickAssar</dc:creator>
      <dc:date>2023-05-06T02:59:30Z</dc:date>
    </item>
  </channel>
</rss>

