<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect, multiple user-selectable endpoints? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-multiple-user-selectable-endpoints/m-p/23399#M17056</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible to have more than one gateway on a public IP, but you have to use different ports, loopback interfaces and NAT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3457"&gt;Can GlobalProtect Portal Page be Configured to be Accessed on any Port?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you expect the user to chose the right VPN for himself? I don't think they will even care to change the configuration just because they are in an untrusted network. Or do you have users who know that they shouldn't access the company network from untrusted networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only have one portal/gateway if you don't have a portal license. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Jan 2015 13:24:28 GMT</pubDate>
    <dc:creator>Wenar</dc:creator>
    <dc:date>2015-01-14T13:24:28Z</dc:date>
    <item>
      <title>GlobalProtect, multiple user-selectable endpoints?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-multiple-user-selectable-endpoints/m-p/23397#M17054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to setup two different versions of GlobalProtect SSLVPN endpoints.&amp;nbsp; I already have a single portal + gateway configuration that only routes specific /24s through the VPN.&amp;nbsp; I want to add a second setup that doesn't split-tunnel and instead passes all traffic through the VPN (for use on untrusted networks like public wifi).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to create an entirely separate Portal as well as Gateway config?&amp;nbsp; Or can I have a single Portal, but multiple gateway configurations, and depending on which hostname is entered in the client config it will change the behavior?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be nice to be able to share a public IP for this, but if that's not possible it isn't a deal-breaker (we have a /24).&amp;nbsp; I *can* reuse the same SSL certificate because it is a wildcard, so different hostnames for the different endpoints isn't a problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jan 2015 08:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-multiple-user-selectable-endpoints/m-p/23397#M17054</guid>
      <dc:creator>bradenmcg</dc:creator>
      <dc:date>2015-01-14T08:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect, multiple user-selectable endpoints?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-multiple-user-selectable-endpoints/m-p/23398#M17055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When configuring multiple gateways they cannot be on the same ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jan 2015 11:31:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-multiple-user-selectable-endpoints/m-p/23398#M17055</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2015-01-14T11:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect, multiple user-selectable endpoints?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-multiple-user-selectable-endpoints/m-p/23399#M17056</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible to have more than one gateway on a public IP, but you have to use different ports, loopback interfaces and NAT:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3457"&gt;Can GlobalProtect Portal Page be Configured to be Accessed on any Port?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you expect the user to chose the right VPN for himself? I don't think they will even care to change the configuration just because they are in an untrusted network. Or do you have users who know that they shouldn't access the company network from untrusted networks?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only have one portal/gateway if you don't have a portal license. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Jan 2015 13:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-multiple-user-selectable-endpoints/m-p/23399#M17056</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2015-01-14T13:24:28Z</dc:date>
    </item>
  </channel>
</rss>

