<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple external IP's and Global protect (Not NAT) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1844#M1370</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;I did a search on the forums for multiple IP's and found a lot of posts talking about how the Palo deals with multiple external IP's - i.e. if your ISP assigns you a /29 block and you need to NAT multiple application into your network. So basically you pick one IP, load that on the Palo interface and then just do NAT. Palo will ARP for any additional IP's used in NAT rules without the need to load those additional IP's on the Palo interface. I would prefer to load the IP's on the interface regardless of NAT because then you can see which external IP's has been allocated to the Palo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;This post kinda touch on the need to have additional IP's loaded somewhere on the Palo, but it is not for NAT, it’s for Global Protect. How do I go about loading the additional external IP's from the /29 block on the Palo box to use in my Global Protect configuration? - i.e. I need one external IP for the gateway and another for the portal. Or what is the recommended way of setting this up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 May 2012 08:18:41 GMT</pubDate>
    <dc:creator>Quinton</dc:creator>
    <dc:date>2012-05-25T08:18:41Z</dc:date>
    <item>
      <title>Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1844#M1370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;I did a search on the forums for multiple IP's and found a lot of posts talking about how the Palo deals with multiple external IP's - i.e. if your ISP assigns you a /29 block and you need to NAT multiple application into your network. So basically you pick one IP, load that on the Palo interface and then just do NAT. Palo will ARP for any additional IP's used in NAT rules without the need to load those additional IP's on the Palo interface. I would prefer to load the IP's on the interface regardless of NAT because then you can see which external IP's has been allocated to the Palo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;This post kinda touch on the need to have additional IP's loaded somewhere on the Palo, but it is not for NAT, it’s for Global Protect. How do I go about loading the additional external IP's from the /29 block on the Palo box to use in my Global Protect configuration? - i.e. I need one external IP for the gateway and another for the portal. Or what is the recommended way of setting this up?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top:0cm;margin-right:0cm;margin-left:0cm;margin-bottom:0.0001pt"&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 08:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1844#M1370</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2012-05-25T08:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1845#M1371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...You can load additional IPs onto the interface simply by adding them with a /32 mask to denote a single host.&amp;nbsp; Here's an example of adding .2 and .3 to an existing interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Global Protect, you can assign the IP/32 to a loopback interface.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="file:/C:/Users/vnguyen/AppData/Local/Temp/moz-screenshot-2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 May 2012 14:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1845#M1371</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-25T14:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1846#M1372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can directly select interface and 32bit IP Address which assigned .1/24 .2/32 .3/32 at GP setting window.&lt;/P&gt;&lt;P&gt;Which is better to use for GP, direct inteface or loopback interface?&lt;/P&gt;&lt;P&gt;I want to the specific reason why you answers using loopback I/F.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 May 2012 05:55:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1846#M1372</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2012-05-28T05:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1847#M1373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think (just guessing) that using loopback would be better in Active/Active situations.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 May 2012 06:48:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1847#M1373</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-28T06:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1848#M1374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use a loopback interface whenever you don't want to tie it to a physical port and to have more flexibility.&amp;nbsp; You may be connected to several ISPs but don't want to assign an IP/32 to a port in case the port goes down.&amp;nbsp; Using the loopback would allow the IP/32 to be reachable across all ports and not be affected by port goin up &amp;amp; down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 May 2012 15:01:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1848#M1374</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-05-29T15:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1849#M1375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know I'm reviving an old thread, but I figured I'd toss this tip in there too in case anyone else stumbles across this thread...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also build untagged subinterfaces off a main interface if for some reason you want your multiple assigned IP addresses to be in separate zones&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you can have your main eth1/1 interface, and then have eth1/1.1 be in zone untrust1, eth1/1.2 be in zone untrust2, eth1/1.2 be in zone untrust3, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "untagged subinterface" part is so that you don't have to convert the interface to a trunk port - the subinterfaces are logically separate, but don't correlate to specific VLANs (which is the normal way one thinks of subinterfaces e.g. on a router with a switch)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 22:09:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1849#M1375</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-01-29T22:09:33Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1850#M1376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I cannot seem to duplicate this.&amp;nbsp; I keep getting Operation Failed: &lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ebedee;"&gt;units -&amp;gt; ethernet1/1.2 constraints failed : tag is required&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Am I missing a step somewhere?&amp;nbsp; I would like to have a second external ip assigned on a sub-interface of eth 1/1 so that I can manage that traffic differently with an "Untrust-VPN" zone.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 20:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1850#M1376</guid>
      <dc:creator>AIC_Admin</dc:creator>
      <dc:date>2013-03-04T20:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple external IP's and Global protect (Not NAT)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1851#M1377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I found what I needed here for anyone who may need it as I did.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1884" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2013 20:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-external-ip-s-and-global-protect-not-nat/m-p/1851#M1377</guid>
      <dc:creator>AIC_Admin</dc:creator>
      <dc:date>2013-03-04T20:56:38Z</dc:date>
    </item>
  </channel>
</rss>

