<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Portal has a problem with DHCP Ext interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22255#M16220</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure what you mean.&amp;nbsp; When you configure the Portal interface to be a L3 interface that's dynamically addressed the IP address is already set to None.&amp;nbsp; Could you please elaborate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Oct 2012 10:34:46 GMT</pubDate>
    <dc:creator>jwolach</dc:creator>
    <dc:date>2012-10-17T10:34:46Z</dc:date>
    <item>
      <title>GlobalProtect Portal has a problem with DHCP Ext interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22251#M16216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm hoping that someone from PAN Support or Development can answer this question.&amp;nbsp; I have been fighting with this for weeks now and have narrow the problem down to the GP Portal service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="text-decoration: underline;"&gt;Scenario&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have a PA-200 in my lab with two Layer3 interfaces defined.&amp;nbsp; The Internal L3 interface has a Static IP for the local network, while the other L3 interface gets it's IP Dynamically from the Comcast ISP.&amp;nbsp; I configured my GlobalProtect Portal &amp;amp; External Gateway to use the L3 interface that is dynamically addressed.&amp;nbsp; From the Public side, users can access the Portal and Gateway just fine.&amp;nbsp; From the local network, users cannot access the Portal or Gateway, even though I have configured my Source-NAT to not NAT traffic sourced from the LAN destined for the Public IP address.&amp;nbsp; Now, here's where it gets weird.&amp;nbsp; I have other computers on my local network that have Public DNS names, so I've created U-Turn NATs to access these devices.&amp;nbsp; Everything works great!&amp;nbsp; I even took away the GP Portal &amp;amp; Gateway from the Public IP interface and tried NATting traffic for the Portal &amp;amp; Gateway to Loopback addresses.&amp;nbsp; Same problem, even worst.&amp;nbsp; Not even users from the Public side can connect to the Portal &amp;amp; Gateway while the Public IP is dynamically assigned.&amp;nbsp; When I make the Public interface a Static IP address everything, including the GP Portal &amp;amp; Gateway NATted to the loopback works great.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems to be an issue with the GP Portal &amp;amp; Gateway service when trying to connect if the IPs are dynamically assigned on the interface they are bound to or being NATted from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Can someone in PAN Support or Development please shed some light on this issue?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Jeff &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Oct 2012 19:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22251#M16216</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-15T19:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal has a problem with DHCP Ext interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22252#M16217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just to clearify regarding your user from local network, that is not to reach users on the public network but rather setup a VPN (or whatever) towards the portal-ip just like the public users?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If its the later - what about if your local users connect to the internal L3 ip instead?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should be able to deal with this by the help of the dns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the user is externally then your external authoritive dns-server will reply to "vpn.example.com" with the external ip. But when they are on the inside your internal authoritive dns-servers (or if you have the same hardware for both cases then use views in your dnsserver) will reply to "vpn.example.com" with the internal ip.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 02:30:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22252#M16217</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-16T02:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal has a problem with DHCP Ext interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22253#M16218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the suggestion.&amp;nbsp; However, this is a workaround and not a solution to a problem with the PAN OS.&amp;nbsp; I really would like to find out why I have a problem with a DHCP addressed interface and not a Statically addressed interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 00:28:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22253#M16218</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-17T00:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal has a problem with DHCP Ext interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22254#M16219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont know if its the case you are facing but a solution for a similar question was to remove the ip address you specify in the portal configuration (in the PA box).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 09:05:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22254#M16219</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-17T09:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal has a problem with DHCP Ext interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22255#M16220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure what you mean.&amp;nbsp; When you configure the Portal interface to be a L3 interface that's dynamically addressed the IP address is already set to None.&amp;nbsp; Could you please elaborate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 10:34:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22255#M16220</guid>
      <dc:creator>jwolach</dc:creator>
      <dc:date>2012-10-17T10:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal has a problem with DHCP Ext interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22256#M16221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry for the confusion... I was most likely thinking of the stuff you already have done (the same stuff as described in &lt;A __default_attr="18406" __jive_macro_name="message" class="jive_macro jive_macro_message" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt; )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 20:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-has-a-problem-with-dhcp-ext-interface/m-p/22256#M16221</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-17T20:49:04Z</dc:date>
    </item>
  </channel>
</rss>

