<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Gateway Behind Nginx Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564407#M114212</link>
    <description>&lt;P&gt;Hello everyone! My environment only has one public IPv4 so I'm trying to make the most of it. We already run a number of web services on port 80/443 behind an Nginx reverse proxy. I'm trying to add GlobalProtect to the mix. I have my portal and gateway running on the same IP. When I forward the ports (80, 443, 4501) the portal seems to work correctly but the gateway just fails. Everything in my FW GP logs says success and my client logs just have a generic "no route" error. Sometimes they connect and can't pass traffic. I've done. Bunch of testing and what I've found is that port 443 needs to be forwarded/streamed directly to the FW otherwise clients fail. Does anyone know why this is or what setting I need to tweak to get the gateway to work behind Nginx?&lt;/P&gt;</description>
    <pubDate>Sat, 04 Nov 2023 22:15:06 GMT</pubDate>
    <dc:creator>MeCJay12</dc:creator>
    <dc:date>2023-11-04T22:15:06Z</dc:date>
    <item>
      <title>GlobalProtect Gateway Behind Nginx Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564407#M114212</link>
      <description>&lt;P&gt;Hello everyone! My environment only has one public IPv4 so I'm trying to make the most of it. We already run a number of web services on port 80/443 behind an Nginx reverse proxy. I'm trying to add GlobalProtect to the mix. I have my portal and gateway running on the same IP. When I forward the ports (80, 443, 4501) the portal seems to work correctly but the gateway just fails. Everything in my FW GP logs says success and my client logs just have a generic "no route" error. Sometimes they connect and can't pass traffic. I've done. Bunch of testing and what I've found is that port 443 needs to be forwarded/streamed directly to the FW otherwise clients fail. Does anyone know why this is or what setting I need to tweak to get the gateway to work behind Nginx?&lt;/P&gt;</description>
      <pubDate>Sat, 04 Nov 2023 22:15:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564407#M114212</guid>
      <dc:creator>MeCJay12</dc:creator>
      <dc:date>2023-11-04T22:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway Behind Nginx Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564412#M114213</link>
      <description>&lt;P&gt;You don't need to run GlobalProtect portal and gateway on WAN interface.&lt;/P&gt;
&lt;P&gt;You can run them on DMZ interface for example and use NAT.&lt;/P&gt;
&lt;P&gt;In this case you can DNAT any port and don't need to use defaults (portal tcp/443 and gateway udp/4501).&lt;/P&gt;</description>
      <pubDate>Sun, 05 Nov 2023 06:08:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564412#M114213</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-11-05T06:08:01Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway Behind Nginx Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564416#M114214</link>
      <description>&lt;P&gt;Thanks for the reply. This is a good idea to eliminate the reverse proxy (which I'm a fan of). I gave it a try this morning and maybe I have something else going on but it didn't quite work either. I have the portal using 80/443 behind the reverse proxy (which in my testing so far hasn't been an issue) and I have the gateway DNAT'd from 8443 to 443 and 4501 to 4501. I can connect immedeatly but then the VPN doesn't allow TCP traffic. ICMP and DNS work fine but websites all get err_time_out and this is consistant to external and internal IPs. I can see the traffic coming through in the traffic logs and being allowed without any errors or anything. The logs don't seem to have any errors. Any ideas?&lt;/P&gt;</description>
      <pubDate>Sun, 05 Nov 2023 15:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564416#M114214</guid>
      <dc:creator>MeCJay12</dc:creator>
      <dc:date>2023-11-05T15:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway Behind Nginx Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564525#M114232</link>
      <description>&lt;P&gt;Found the second issue. I was testing external user access from a T-Moblie internet connection. Apparently T-Mobile requires lowering the GlobalProtect MTU. For anyone coming across this in the future, I lowered it to 1280 for the time being. I may try raising/tweaking it again later.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Nov 2023 15:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-behind-nginx-issue/m-p/564525#M114232</guid>
      <dc:creator>MeCJay12</dc:creator>
      <dc:date>2023-11-06T15:25:21Z</dc:date>
    </item>
  </channel>
</rss>

