<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN (with Global Protect) and reserved IP for one user in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34968#M25670</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an expected error, the minimum subnet to create a gateway pool is /30. What you can try is to configure a pool in a different gateway just for that specific user. He will get the same IP address i.e. the 1st IP address from that pool every time he disconnects and connect back as there would be no other users who would be using that defined pool. This is just a workaround, what I would also suggest if you can do a feature request so that a user can be assigned a specific IP address based on HIP match, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Khubaib Alavi &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2012 04:20:56 GMT</pubDate>
    <dc:creator>kalavi</dc:creator>
    <dc:date>2012-10-05T04:20:56Z</dc:date>
    <item>
      <title>SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34961#M25663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use basic global protect functionality (no global protect licenses) to connect with SSL VPN. One of user (businnes owner) must have always the same IP address when he connect via SSL VPN. How can I resolve this? In global protect configuration isn't possible to reserve IP addresses for MAC address (like in DHCP server).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2012 12:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34961#M25663</guid>
      <dc:creator>darkfibre</dc:creator>
      <dc:date>2012-05-17T12:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34962#M25664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;MAC addres reservations for DHCP work because the firewall gets teh DHCP request and can evaluate the MAC address. For such a feature to work for VPN users, the VPN client would have to sent it's MAC address as part of the authentication process. From the firewall's point of view, every VPN connection comes from the router's MAC address since they all come from outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not aware of such a capability but perhaps someone else has a solution for this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2012 16:37:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34962#M25664</guid>
      <dc:creator>npare</dc:creator>
      <dc:date>2012-05-17T16:37:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34963#M25665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of my client has a similar requirement to reserve IP Address while connecting to Global protect SSL VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to achieve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jun 2012 10:27:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34963#M25665</guid>
      <dc:creator>support.sec</dc:creator>
      <dc:date>2012-06-27T10:27:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34964#M25666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A form of this functionality can be obtained by configuring a user specific client configuration on your portal that points to a second external gateway.&amp;nbsp; The second gateway would be configured to only distribute one IP address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This capability exists for the more common use case of defining specific user groups that might get different configurations and networks settings, so it doesn't really scale to doing this for dozens of individual IPs, but for a one-off it should work fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jun 2012 16:37:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34964#M25666</guid>
      <dc:creator>drogers</dc:creator>
      <dc:date>2012-06-28T16:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34965#M25667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi drogers.&lt;/P&gt;&lt;P&gt;When I try to configure "Cliente Configuration" into Globalprotect Gateway with only one IP address, I obtain this message: "SSLVPN: Invalid IP pool value: X.X.X.X. Subnet is smaller than minimum allowed value 30." Is it not possible to configure only one IP in a pool? What is the reason for it?&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2012 13:30:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34965#M25667</guid>
      <dc:creator>jmrodriguez</dc:creator>
      <dc:date>2012-07-10T13:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34966#M25668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get the same problem for a customer of mine...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get the same error when i try to allow a specific address in the IP Pool : "&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;SSLVPN: Invalid IP pool value: X.X.X.X. Subnet is smaller than minimum allowed value 30."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an issue or a patch for this problem ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2012 08:55:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34966#M25668</guid>
      <dc:creator>jonathan_delannoye</dc:creator>
      <dc:date>2012-08-21T08:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34967#M25669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone ever get this working? Based on the responses I've got this still isn't possible and even having multiple gateways won't fix it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2012 18:02:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34967#M25669</guid>
      <dc:creator>jmahoney</dc:creator>
      <dc:date>2012-10-04T18:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34968#M25670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is an expected error, the minimum subnet to create a gateway pool is /30. What you can try is to configure a pool in a different gateway just for that specific user. He will get the same IP address i.e. the 1st IP address from that pool every time he disconnects and connect back as there would be no other users who would be using that defined pool. This is just a workaround, what I would also suggest if you can do a feature request so that a user can be assigned a specific IP address based on HIP match, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Khubaib Alavi &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 04:20:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34968#M25670</guid>
      <dc:creator>kalavi</dc:creator>
      <dc:date>2012-10-05T04:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN (with Global Protect) and reserved IP for one user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34969#M25671</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also operate NAT Source Translation on the pool. It was advised by a Palo Alto engineer to do it like that because it's not possible to allocate only one IP Address (what a simple PIX do &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 07:27:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-with-global-protect-and-reserved-ip-for-one-user/m-p/34969#M25671</guid>
      <dc:creator>jonathan_delannoye</dc:creator>
      <dc:date>2012-10-05T07:27:21Z</dc:date>
    </item>
  </channel>
</rss>

