<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect and two gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33175#M24320</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning Slawek,&lt;/P&gt;&lt;P&gt;For a multiple gateway scenario, ensure that you have the multiple gateway licenses. In addition to that, the GP users when connecting to the firewalls, would always first authenticate on the portal and then to the gateway. If the users have to be authenticated via Radius, create an authentication sequence that uses both the LDAP and the Radius and use this sequence under the portal authentication, so that if the users connecting to the gateway2, cannot be authenticated via LDAP, then they can fall back to the Radius Authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once they get authenticated, they next connect to the gateway. Ensure that you are using the same Radius server for authenticating when connecting to the Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can connect to a gateway manually. See the below link that has a video explaining the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/videos/1275"&gt;https://live.paloaltonetworks.com/videos/1275&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Jun 2013 13:52:03 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-06-24T13:52:03Z</dc:date>
    <item>
      <title>Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33171#M24316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have PA200 without licence for second GP Portal.&lt;/P&gt;&lt;P&gt;I did a second gateway because I thought that this should solve my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to let access to some website to my users but with my IP address. Thease people has accounts on radius server. I did second gateway for them.&lt;/P&gt;&lt;P&gt;I have separate IP and SSL certyfiacate for this, separate config (different VPN network, tunnel interface, authentication profile).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when I try to point to GP Client to use gateway2 as a portal it's complain about certificate. I know that I sould put there a portal url not gateway! - but how to tell to GP client to use second gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On my first gateway are logging peopple that has accounts on ActiveDirectory or locally on PA device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought of using only one gateway but then I will be unable to recognize users in security policies (create rules for users fro AD different that from Radius.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry for my english ... but I hope that you undertand what I'm trying to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I'm wrong - in which situation we are using more than one gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 11:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33171#M24316</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-24T11:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33172#M24317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you configured 2 portals and 2 gateway ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 11:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33172#M24317</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-24T11:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33173#M24318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I configured one portal and two gateways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 11:43:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33173#M24318</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-24T11:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33174#M24319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"But when I try to point to GP Client to use gateway2 as a portal it's complain about certificate"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't do that.every client should connect to portal first.&lt;/P&gt;&lt;P&gt;you need a license for 2 gateways&lt;/P&gt;&lt;P&gt;without license you can only use&lt;/P&gt;&lt;P&gt;2portals each have one gateway&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 11:47:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33174#M24319</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-24T11:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33175#M24320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning Slawek,&lt;/P&gt;&lt;P&gt;For a multiple gateway scenario, ensure that you have the multiple gateway licenses. In addition to that, the GP users when connecting to the firewalls, would always first authenticate on the portal and then to the gateway. If the users have to be authenticated via Radius, create an authentication sequence that uses both the LDAP and the Radius and use this sequence under the portal authentication, so that if the users connecting to the gateway2, cannot be authenticated via LDAP, then they can fall back to the Radius Authentication. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once they get authenticated, they next connect to the gateway. Ensure that you are using the same Radius server for authenticating when connecting to the Gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can connect to a gateway manually. See the below link that has a video explaining the same:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/videos/1275"&gt;https://live.paloaltonetworks.com/videos/1275&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 13:52:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33175#M24320</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-24T13:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33176#M24321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hmm thats interesting why my PA200 dosn't complain about licences during commit proces (when I have one portal and two gateways)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 10:32:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33176#M24321</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-25T10:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33177#M24322</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is because you are configuring Global protect gateway but inside Global Protect Portal defining 2 gateways will change the behaviour.you will get notification for license.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 10:50:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33177#M24322</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-25T10:50:55Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and two gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33178#M24323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for all of you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now i have two portals and it's seems to be working.&lt;/P&gt;&lt;P&gt;I know that I can use authentication sequence but for second GP portal there must by Radius only auth. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have to do NAT with special IP for second GP gateway. I did nat rule with filter for source adresses (second gateway has different network adresses than first) but I stuck with security policy.&lt;/P&gt;&lt;P&gt;Because both of my GP are in the same zone (on PA200 I have very limited amount of zones) I need to use filter for source addresses. Do I have other options? Can I select users authenticated by radius server? ( I can't see such option but maybe I'm wrong...).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My security polices:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-06-25_131832.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7082_2013-06-25_131832.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;and security policies&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2013-06-25_131810.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7083_2013-06-25_131810.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;In this situation do I need "GP to internet" or "VPN NAT" is enought?&lt;/P&gt;&lt;P&gt;I put "GP blokada" right after allow policies because I need to limit access to internet only - is it correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 11:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-and-two-gateway/m-p/33178#M24323</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-25T11:29:07Z</dc:date>
    </item>
  </channel>
</rss>

