<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accessing all company networks with GlobalProtect client in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31836#M23296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't tell, have no access to appliance. But VPN works fine: main - brunch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Sep 2013 12:17:35 GMT</pubDate>
    <dc:creator>kpv</dc:creator>
    <dc:date>2013-09-23T12:17:35Z</dc:date>
    <item>
      <title>Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31832#M23292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basic info:&lt;/P&gt;&lt;P&gt;PA-500 (software version 5.0.7)&lt;/P&gt;&lt;P&gt;Main location network: 10.10.1.0/24&lt;/P&gt;&lt;P&gt;Branch location network: 192.168.1.0/24&lt;/P&gt;&lt;P&gt;GlobalProtect client IP pool: 10.10.3.10 - 10.10.3.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have main location network and branch location network connected thru IPSec VPN. Our PA-500 is located on main location and handles GlobalProtect clients connections. When we connect thru GlobalProtect client, we are able to access only main location network, but cannot access branch network. How to configure that? By adding another proxy ID to IPSec tunnel? (local: 10.10.3.0/24, remote: 192.168.1.0/24 in main location and vice versa on branch location)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 11:03:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31832#M23292</guid>
      <dc:creator>kpv</dc:creator>
      <dc:date>2013-09-23T11:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31833#M23293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What did you configure for access route ? (Global Protect configuration)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 11:08:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31833#M23293</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-23T11:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31834#M23294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Access route:&lt;/P&gt;&lt;P&gt;10.10.1.0/24&lt;/P&gt;&lt;P&gt;192.168.1.0/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And i forgot to tell before: I don't know what appliance is at the other end of tunnel (main - branch). Someone else will configure that one.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 11:25:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31834#M23294</guid>
      <dc:creator>kpv</dc:creator>
      <dc:date>2013-09-23T11:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31835#M23295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have set route on Branch location to Main location as well?&lt;/P&gt;&lt;P&gt;Know as back route.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 12:03:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31835#M23295</guid>
      <dc:creator>hsnetworks01</dc:creator>
      <dc:date>2013-09-23T12:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31836#M23296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't tell, have no access to appliance. But VPN works fine: main - brunch.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 12:17:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31836#M23296</guid>
      <dc:creator>kpv</dc:creator>
      <dc:date>2013-09-23T12:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31837#M23297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VPN can works as is independent on route.&lt;/P&gt;&lt;P&gt;Steps:&lt;/P&gt;&lt;P&gt;create VPN&lt;/P&gt;&lt;P&gt;set route&lt;/P&gt;&lt;P&gt;set security rules&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 12:37:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31837#M23297</guid>
      <dc:creator>hsnetworks01</dc:creator>
      <dc:date>2013-09-23T12:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31838#M23298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then you just need a source NAT rule.&lt;/P&gt;&lt;P&gt;(if you have security rule)&lt;/P&gt;&lt;P&gt;Write a NAT rule for source address &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;10.10.3.10 - 10.10.3.254&lt;/SPAN&gt; and also select zone, destination zone as branch and source NAT dynamic ip port / interface select Main Location interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you should access to branch without problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 13:19:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31838#M23298</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-23T13:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31839#M23299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for now. I will look into security and will be back.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 13:50:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31839#M23299</guid>
      <dc:creator>kpv</dc:creator>
      <dc:date>2013-09-23T13:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31840#M23300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello kpv,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I understand from your description that only the Branch location network is inaccessible by the GP users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have,&lt;/P&gt;&lt;P&gt;1. Proxy Id for the GP subnet and remote subnet (if doing a policy based ipsec vpn)&lt;/P&gt;&lt;P&gt;2. Security policy from GP-tunnel zone to the Ipsec-tunnel zone on the PA500.&lt;/P&gt;&lt;P&gt;3. Return route/access from branch network to the GP subnet on the Peer side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Aditi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 16:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31840#M23300</guid>
      <dc:creator>apasupulati</dc:creator>
      <dc:date>2013-09-23T16:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: Accessing all company networks with GlobalProtect client</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31841#M23301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Was just having the same problem.&amp;nbsp; Turned out to be a return route as &lt;A href="https://live.paloaltonetworks.com/u1/9112"&gt;apasupulati&lt;/A&gt; suggested in item #3 of his post. Similar setup here in this post: &lt;A href="https://live.paloaltonetworks.com/thread/8738"&gt;Client VPN traffic and routing over IPsec Tunnel&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 21:21:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/accessing-all-company-networks-with-globalprotect-client/m-p/31841#M23301</guid>
      <dc:creator>cmateam</dc:creator>
      <dc:date>2013-09-23T21:21:32Z</dc:date>
    </item>
  </channel>
</rss>

