<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN with two subnets in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263612#M126964</link>
    <description>&lt;P&gt;Hello Jay,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for responding.&amp;nbsp; &amp;nbsp;I meant under GP&amp;gt;Gateways&amp;gt;agent&amp;gt;Client_Settings&amp;gt; i created another client and move it up to the top so it can be checked first.&amp;nbsp; I have it configured to check if the user that connects is x person to give an IP from that IP pool.&amp;nbsp; &amp;nbsp;the other client settings under is for everybody else to use another set of IP addresses(this has always worked fine).&amp;nbsp; &amp;nbsp; ON the GP&amp;gt;portals, authentication profile, it's the same SAML for both client settings.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to mentioned this works fine with the original client settings, i connect with the x username no problem, but somehow it's ignoring the first client settings and it's giving me IP address from the second client settings.&lt;/P&gt;
&lt;P&gt;thanks again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;YP&lt;/P&gt;</description>
    <pubDate>Thu, 03 Sep 2026 20:05:22 GMT</pubDate>
    <dc:creator>YParreno</dc:creator>
    <dc:date>2026-09-03T20:05:22Z</dc:date>
    <item>
      <title>VPN with two subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263512#M126954</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are using globalprotect for users to connect to our network, but recently we have another set of users that we would like to put them on a separate network.&amp;nbsp; &amp;nbsp;We created another profile on the Gateway specifying that if certain users, we have connection with SAML, should receive the IP address of the secondary subnet. We moved this profile to the top, to be the first one.&amp;nbsp; However is not working, they still receiving the IP from the other subnets configured long time ago.&amp;nbsp; if any help, i would appreciate.&lt;BR /&gt;#vpngateways #globalprotect&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2026 14:46:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263512#M126954</guid>
      <dc:creator>YParreno</dc:creator>
      <dc:date>2026-09-02T14:46:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with two subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263539#M126957</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/211357"&gt;@YParreno&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you explain what you mean by creating another profile on the gateway? Do you mean that you created a new client auth profile for these new users and specified the auth profile to be SAML? And then create a Client Agent config profile? Also, for the existing client auth profile, what type of auth are you using there?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2026 00:14:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263539#M126957</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-09-03T00:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with two subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263612#M126964</link>
      <description>&lt;P&gt;Hello Jay,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks for responding.&amp;nbsp; &amp;nbsp;I meant under GP&amp;gt;Gateways&amp;gt;agent&amp;gt;Client_Settings&amp;gt; i created another client and move it up to the top so it can be checked first.&amp;nbsp; I have it configured to check if the user that connects is x person to give an IP from that IP pool.&amp;nbsp; &amp;nbsp;the other client settings under is for everybody else to use another set of IP addresses(this has always worked fine).&amp;nbsp; &amp;nbsp; ON the GP&amp;gt;portals, authentication profile, it's the same SAML for both client settings.&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to mentioned this works fine with the original client settings, i connect with the x username no problem, but somehow it's ignoring the first client settings and it's giving me IP address from the second client settings.&lt;/P&gt;
&lt;P&gt;thanks again.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;YP&lt;/P&gt;</description>
      <pubDate>Thu, 03 Sep 2026 20:05:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263612#M126964</guid>
      <dc:creator>YParreno</dc:creator>
      <dc:date>2026-09-03T20:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN with two subnets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263678#M126969</link>
      <description>&lt;P&gt;you'll need to check if the username (or group mapping) you've added _exactly_ matches the username as it is received by globalprotect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;eg, if the usermapping is registered as &lt;A href="mailto:user@domain" target="_blank"&gt;user@domain&lt;/A&gt;&amp;nbsp;and you added domain\user as matching condition for the second profile, the profile will not match for the user and they will fall down to the next profile&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2026 11:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-with-two-subnets/m-p/1263678#M126969</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-09-04T11:06:25Z</dc:date>
    </item>
  </channel>
</rss>

