<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect expand IP Pool in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/614427#M121409</link>
    <description>&lt;P&gt;I found the issue. We had legacy config that included other GP Gateways and IP Pools. One of the pools had an overlapping IP range, so any client that received an IP from the new gateway in the overlapping portion of the range would still connect and get an IP, but traffic wouldn't flow. Removed the old gateway config and it's working fine now.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2024 15:14:23 GMT</pubDate>
    <dc:creator>MikeSangray2019</dc:creator>
    <dc:date>2024-10-24T15:14:23Z</dc:date>
    <item>
      <title>GlobalProtect expand IP Pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/600083#M119280</link>
      <description>&lt;P&gt;We have an existing GP setup and it's working, but the IP Pool is set to a range of IPs 192.168.10.10-192.168.10.100 instead of a subnet 192.168.10.0/24.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to either expand the range or change it to a subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested this by expanding the range to 192.168.10.5-192.168.10.150, but clients that got an address in the newly expanded range e.g. 192.168.10.125 were having trouble with network traffic like connecting to internal DNS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I looked at traffic logs, etc., but nothing stood out as the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there other places in the config I need to change the range or commands I need to run?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Policies already allow by zone. Routing is already configured to use the /24 subnet.&lt;BR /&gt;I did see traffic being allowed, but maybe replies weren't being routed correctly back to the expanded range?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe a routing table issue?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 18:43:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/600083#M119280</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2024-10-10T18:43:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect expand IP Pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/600102#M119281</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That should be the only spot where you should have to specify the IP range It sounds like it possible you may now have a return route on an upstream device (or maybe you have multiple VRs and they dont have a route between each other for the ne network. I would next look at doing a packet catpure on the Palo to see if you are getting return traffic at all. If you are and its being dropped I would then check the global counters to see why its being dropped.&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CloNCAS" target="_blank"&gt;How to check global counters for a specific source and destinat... - Knowledge Base - Palo Alto Networks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Oct 2024 19:41:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/600102#M119281</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-10-10T19:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect expand IP Pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/600251#M119293</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124213"&gt;@MikeSangray2019&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;We have an existing GP setup and it's working, but the IP Pool is set to a range of IPs 192.168.10.10-192.168.10.100 instead of a subnet 192.168.10.0/24.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want to either expand the range or change it to a subnet.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tested this by expanding the range to 192.168.10.5-192.168.10.150, but clients that got an address in the newly expanded range e.g. 192.168.10.125 were having trouble with network traffic like connecting to internal DNS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I looked at traffic logs, etc., but nothing stood out as the issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there other places in the config I need to change the range or commands I need to run?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Policies already allow by zone. Routing is already configured to use the /24 subnet.&lt;BR /&gt;I did see traffic being allowed, but maybe replies weren't being routed correctly back to the expanded range?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe a routing table issue?&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Sounds like it could be a routing issue.&amp;nbsp; What type of routing are you doing, static or dynamic?&amp;nbsp; After you changed your GP IP pool did you update your routing for the previous IP pool to include the new network space?&amp;nbsp; You would potentially need to update the route in multiple areas on the firewall or even outside the FW if you're using static routing.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 13:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/600251#M119293</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-10-11T13:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect expand IP Pool</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/614427#M121409</link>
      <description>&lt;P&gt;I found the issue. We had legacy config that included other GP Gateways and IP Pools. One of the pools had an overlapping IP range, so any client that received an IP from the new gateway in the overlapping portion of the range would still connect and get an IP, but traffic wouldn't flow. Removed the old gateway config and it's working fine now.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2024 15:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-expand-ip-pool/m-p/614427#M121409</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2024-10-24T15:14:23Z</dc:date>
    </item>
  </channel>
</rss>

