<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect on overlapping networks in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35787#M26297</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No not necessarily.&amp;nbsp; For instance, I have 2 rules on my Vrouter for 172 and 192 addresses that point them from my external interface to my internal gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Oct 2011 15:45:01 GMT</pubDate>
    <dc:creator>kamish</dc:creator>
    <dc:date>2011-10-11T15:45:01Z</dc:date>
    <item>
      <title>Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35779#M26289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everybody!&lt;/P&gt;&lt;P&gt;I have a big problem with Global Protect and overlapping networks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I make you an example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;My local network is 192.168.10.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My Global Protect Network is 172.16.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The external network has the same class of my local network&lt;/P&gt;&lt;P&gt;--------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I connect my lapton in any networks everything works good but if the network has the same class of my local network Global Protec Client on my laptop discover the "outside network" like extenal network (perfect thing) but if I try to access some service like webserver or Exchange I encounter connection error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I resolve this specific situation? How?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another think ... I can resolve and ping for example my internal DNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Help me please ....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:20:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35779#M26289</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-11T13:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35780#M26290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are hitting your external gateway fine, but are unable to access internal resources?&amp;nbsp; Is this correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:31:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35780#M26290</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T13:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35781#M26291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple places to look for a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check to make sure that you have a security rule in place from inside to outside with your IP range for the GP pool. And vice versa.&lt;/LI&gt;&lt;LI&gt;Check that you have a route in place on your vrouter to allow you to stay inside once you have connected to the GP client.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you upload images of your vrouter and interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, make sure that your IP pool that you are assigning clients from GP is not the same network as your internal resources.&amp;nbsp; It has to be something different.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:37:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35781#M26291</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T13:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35782#M26292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes ... but only some address. For Example the DNS server works good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I've find the error. I've missed the Access Route in Gateway configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35782#M26292</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-11T13:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35783#M26293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That'll do it.&amp;nbsp; Let me know if that fixes it.&amp;nbsp; If you just enter 0.0.0.0 in the access routes for the Gateway, that will take care of it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:48:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35783#M26293</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T13:48:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35784#M26294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I use 0.0.0.0/0 or leave everything blank I have the overlapping problem.&lt;/P&gt;&lt;P&gt;If I submit my network class everything works but I cannot block for example the web-browsing because I bypass my firewall for navigation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 14:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35784#M26294</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-11T14:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35785#M26295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does your vrouter have a route to internal resources?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 15:23:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35785#M26295</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T15:23:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35786#M26296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you mean I have to create I single route for I single resource in VR?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 15:41:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35786#M26296</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-11T15:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35787#M26297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No not necessarily.&amp;nbsp; For instance, I have 2 rules on my Vrouter for 172 and 192 addresses that point them from my external interface to my internal gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 15:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35787#M26297</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T15:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35788#M26298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is what my vrouter looks like:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 15:51:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35788#M26298</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T15:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35789#M26299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tomorrow I'm going to try your solution. I give you a feedback asap&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 17:41:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35789#M26299</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-11T17:41:10Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35790#M26300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here I'm!&lt;/P&gt;&lt;P&gt;After a morning of test these are the results:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all we've updated the firmware at 4.0.5.&lt;/P&gt;&lt;P&gt;After that we've made a test with our client on external network. The result is not good!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;We are on external network (class: 192.168.10.x/24) and try to connect trought GP at our network (same class but /21). We can ping and reach some IP but not all! For example the Exchange server not respond.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attach the route create by GP client on external notebook and our VR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 13:36:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35790#M26300</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-12T13:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35791#M26301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to your schemata pic, there is not a route in there for 192.168.10.x/24.&amp;nbsp; Honestly, I would remove all of the routes that you have for all of your 192 addresses and just make the route state 192.168.0.0/16 to your gateway.&amp;nbsp; That way anything coming from 192.168 routes to the gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another thing to check would be to make sure that all of your internal DNS issues can resolve.&amp;nbsp; I.E. in your external gateway config do you have the addresses of your DNS servers entered and a DNS suffix?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 13:42:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35791#M26301</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-12T13:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35792#M26302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also, could you show screen shots of your portal and gateway config?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 13:45:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35792#M26302</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-12T13:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35793#M26303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 14:04:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35793#M26303</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-12T14:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35794#M26304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PS: the DNS is configured.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 14:13:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35794#M26304</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-12T14:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35795#M26305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On your portal IP and external gateway IP, are the public or private IPs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If they are private, do you have a NAT rule in place for them to resolve to?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 14:20:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35795#M26305</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-12T14:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35796#M26306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We've got public IP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 14:22:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35796#M26306</guid>
      <dc:creator>LCMember317</dc:creator>
      <dc:date>2011-10-12T14:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35797#M26307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I stated before, there is not a route on your vrouter for 192.168.10.x/24 with next hop being your internal gateway.&amp;nbsp; I would just make a mask 192.168.0.0/16 from your eth1/1 interface to the 192.168.10.253 address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 14:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35797#M26307</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-12T14:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect on overlapping networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35798#M26308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But the fact that your internal gateway IP and inside network gateway are on the same subnet could be an issue as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Oct 2011 14:29:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-on-overlapping-networks/m-p/35798#M26308</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-12T14:29:16Z</dc:date>
    </item>
  </channel>
</rss>

