<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add backup GlobalProtect portal to GlobalProtect client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222654#M123501</link>
    <description>&lt;P&gt;You need to add the second portal from the GP client on the PC. Click the GP client in the taskbar to open, click the menu icon in the upper-right corner and select "Settings", under the Connections section - Manage Portals and click the plus icon to add another Portal. Then you will be able to select the second Portal from the GP client Portal dropdown. You can also push these from a GPO/startup settings, but its a bit of a pain after the fact.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or you could do dual Portal A records and use a single name. Both Portals will need a security certificate with the hostname matching the A record.&lt;/P&gt;</description>
    <pubDate>Wed, 05 Mar 2025 00:18:46 GMT</pubDate>
    <dc:creator>Adrian_Jensen</dc:creator>
    <dc:date>2025-03-05T00:18:46Z</dc:date>
    <item>
      <title>Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222327#M123451</link>
      <description>&lt;P&gt;On our PA-1410 under Network - GlobalProtect - Portals - each of our portals (one on each interface for each ISP) - Agent - Agent Config - External Gateway I added gp2.domain.com to go along with gp.domain.com.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was thinking (hoping) that would update the GlobalProtect client to add the gp2.domain.com to the GlobalProtect client as a failover just in case gp.domain.com was not reachable. Don't care about load balancing the GP clients, just adding a level of redundancy to the client side.&lt;/P&gt;
&lt;P&gt;I don't think I am doing this right and figure there is another way to add a failover portal. Where should I be adding that? Or do I need to do something with the client on each machine?&lt;/P&gt;
&lt;P&gt;Thanks for any pointers!&lt;/P&gt;</description>
      <pubDate>Sat, 01 Mar 2025 01:38:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222327#M123451</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2025-03-01T01:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222335#M123455</link>
      <description>&lt;P&gt;You create only 1 portal.&lt;/P&gt;
&lt;P&gt;Run it on DMZ interface (2x ISP IPs natted to that DMZ IP tcp/80, tcp/443 and udp/4501).&lt;/P&gt;
&lt;P&gt;If your users are ok to add https:// manually in front of the portal to access portal address then 80 is not needed. Otherwise Palo will automatically redirect 80 to 443.&lt;/P&gt;
&lt;P&gt;Set up 2 A records pointing to 2 different ISP IPs (so DNS resolution gives back 2 IPs for same portal).&lt;/P&gt;
&lt;P&gt;Agent picks one of those IPs randomly to connect to portal.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For gateways you set up 2 separate DNS records&lt;/P&gt;
&lt;P&gt;vpn-isp1.company.com&lt;/P&gt;
&lt;P&gt;vpn-isp2.company.com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Run gateway on same DMZ portal natting public IPs to DMZ IP.&lt;/P&gt;
&lt;P&gt;Portal config hands out 2 gateways to agents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Agents perform latency test and connect through ISP that is closer by.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Mar 2025 19:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222335#M123455</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-03-01T19:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222424#M123469</link>
      <description>&lt;P&gt;Appreciate the answer. I have inherited this set up, so all that configuration sounds a bit daunting! Is there anything I can do with the current setup to get the client to add another gateway? Maybe just add another DNS entry externally?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:19:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222424#M123469</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2025-03-03T16:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222438#M123471</link>
      <description>&lt;P&gt;Gateways can be added under:&lt;/P&gt;
&lt;P&gt;Network &amp;gt; GlobalProtect &amp;gt; Portals &amp;gt; Portal-Name &amp;gt; Agent &amp;gt; Agent-config-name &amp;gt; External&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Raido_Rattameister_0-1741020081422.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66288i0C2D32233D358F54/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Raido_Rattameister_0-1741020081422.png" alt="Raido_Rattameister_0-1741020081422.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 16:41:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222438#M123471</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-03-03T16:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222466#M123479</link>
      <description>&lt;P&gt;Thank you. I will give that a shot and see how it goes.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 20:42:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222466#M123479</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2025-03-03T20:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222642#M123498</link>
      <description>&lt;P&gt;I run two portals, each on its own ISP interface and routing tables, with multiple Gateways as well. That way you can have different config options on different Portals/Gateways and redirect clients to one or the other based on demand. It also allows you to have test Portals/Gateways for new configs without disturbing active clients.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 21:16:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222642#M123498</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2025-03-04T21:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222653#M123500</link>
      <description>&lt;P&gt;I added the additional external portals on the PA-1410 but not seeing it on the client. Unless I am not looking in the right place....&lt;/P&gt;
&lt;P&gt;If I go to settings in GP, I see just a single portal listed.&lt;/P&gt;
&lt;P&gt;Should I just have 2x A entries in DNS for gp.domain.com instead?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 23:28:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222653#M123500</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2025-03-04T23:28:43Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222654#M123501</link>
      <description>&lt;P&gt;You need to add the second portal from the GP client on the PC. Click the GP client in the taskbar to open, click the menu icon in the upper-right corner and select "Settings", under the Connections section - Manage Portals and click the plus icon to add another Portal. Then you will be able to select the second Portal from the GP client Portal dropdown. You can also push these from a GPO/startup settings, but its a bit of a pain after the fact.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Or you could do dual Portal A records and use a single name. Both Portals will need a security certificate with the hostname matching the A record.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 00:18:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222654#M123501</guid>
      <dc:creator>Adrian_Jensen</dc:creator>
      <dc:date>2025-03-05T00:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Add backup GlobalProtect portal to GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222796#M123516</link>
      <description>&lt;P&gt;This solution adds additional "Change Gateway" droppdown.&lt;/P&gt;
&lt;P&gt;If it is not visible it means your agent has not refreshed config from portal yet.&lt;/P&gt;
&lt;P&gt;Click on hamburger menu in GlobalProtect agent (3 lines top right) and choose "Refresh Connection" to force config sync from portal to agent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Adding second portal is more cumbersome to the user but can be done from agent itself if needed.&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 16:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/add-backup-globalprotect-portal-to-globalprotect-client/m-p/1222796#M123516</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-03-05T16:18:37Z</dc:date>
    </item>
  </channel>
</rss>

