<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect client behind a proxy, configuration help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41474#M30501</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to establish an ssl vpn connection using the globalprotect client, but the client is behind a proxy using a configuration script.&amp;nbsp; I have tried calling paloalto support but they said their client is not proxy aware.&amp;nbsp; Does anyone know of some things I could try to get the globalprotect ssl vpn client to work from behind a proxy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Nov 2013 21:28:42 GMT</pubDate>
    <dc:creator>bigtone</dc:creator>
    <dc:date>2013-11-15T21:28:42Z</dc:date>
    <item>
      <title>GlobalProtect client behind a proxy, configuration help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41474#M30501</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to establish an ssl vpn connection using the globalprotect client, but the client is behind a proxy using a configuration script.&amp;nbsp; I have tried calling paloalto support but they said their client is not proxy aware.&amp;nbsp; Does anyone know of some things I could try to get the globalprotect ssl vpn client to work from behind a proxy?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Nov 2013 21:28:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41474#M30501</guid>
      <dc:creator>bigtone</dc:creator>
      <dc:date>2013-11-15T21:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client behind a proxy, configuration help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41475#M30502</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;GlobalProtect is indeed proxy-aware. Prior to version 1.2.6 there was a failure to detect a PAC file when connecting to the gateway, but that was resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on how the portal and gateway are reached, you may have to modify the registry if the Gateway and Portal have different directives. From the release notes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;54487— GlobalProtect was failing to automatically discover Web Proxy Autodiscovery Protocol (WPAD) and proxy auto-config (PAC) settings and was not connecting to the proxy portal. This did not occur when the proxy was configured statically using the web interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;54230—GlobalProtect was failing to automatically discover proxy auto-config (PAC) settings and was not connecting to the proxy gateway. With the fix, GlobalProtect will now use the same proxy server for the portal and gateway, as determined from the PAC file. If the PAC file has specific directives to use a different proxy server for the portal and gateway(s), then a registry setting must be added on the client: &lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\PanGPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create a new key named ProxyMultipleAutoDetection, with a type of DWORD and a value of 1. This key is only required if the PAC file specifies a different proxy server for the portal and gateway(s). &lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The challenge may be in the initial discovery of the PAC file, but if using something like wpad.dat or the proxy configuration from Windows (assuming a Windows client) Internet connection settings, GlobalProtect should have no problem connecting using the proxy settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Nov 2013 22:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41475#M30502</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-11-15T22:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client behind a proxy, configuration help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41476#M30503</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply greg, I have notified support.&amp;nbsp; We tried the registry changes and we are still getting a "gateway x.x.x.x: proxy authentication failure." message.&amp;nbsp; Do you have any other suggestions for us?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 21:53:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41476#M30503</guid>
      <dc:creator>bigtone</dc:creator>
      <dc:date>2013-11-22T21:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client behind a proxy, configuration help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41477#M30504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another thing you can try to do is set the proxy settings in the browser manually and test to see if this works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Capture.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/9930_Capture.PNG.png" style="width: 620px; height: 427px;" /&gt;&lt;/P&gt;&lt;P&gt;If doing this works and you have made sure that you are on the latest release of the GP client in which the fix is there as per Greg. I think then you might be running into some bug or configuration issue and will need to open a case with support.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Hope this helps.&lt;BR /&gt;Best Regards, &lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 19:33:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41477#M30504</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-11-25T19:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client behind a proxy, configuration help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41478#M30505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;We use an automatic configuration script but yes I have also tried putting in the ip address and port of the proxy server with the same proxy authentication error.&amp;nbsp; When I do a packet capture while trying to connect I see that the GP client tries to do an HTTP CONNECT to the ssl gateway on port 443.&amp;nbsp; I believe that is what my proxy doesn't like.&amp;nbsp; I think the proxy will allow http on port 80, but not 443.&amp;nbsp; When I manually type in my browser &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://hostname:443"&gt;http://hostname:443&lt;/A&gt;&lt;SPAN&gt; I get this &lt;/SPAN&gt;&lt;/P&gt;&lt;TABLE class="contentTable" style="border-width: 0px; border-style: none; color: #000000; font-family: verdana, helvetica, arial, sans-serif; font-size: 12px; background-color: #ced1d4;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="contentData" style="padding: 5px 10px;"&gt;The Proxy received an invalid response.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;TABLE class="infoTable" style="border-width: 0px; border-style: none; color: #000000; font-family: verdana, helvetica, arial, sans-serif; font-size: 12px; background-color: #ced1d4;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD class="infoData" style="padding: 0 15px;"&gt;&lt;P&gt;&lt;STRONG style="color: #800000;"&gt;URL: &lt;/STRONG&gt;&lt;A class="jive-link-external-small" href="http://67.214.245.37:443/"&gt;http://67.214.245.37:443/&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the packet capture I get an http 407 authentication required from my proxy...any other ideas.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Nov 2013 17:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41478#M30505</guid>
      <dc:creator>bigtone</dc:creator>
      <dc:date>2013-11-27T17:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client behind a proxy, configuration help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41479#M30506</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;An HTTP CONNECT is the correct type of request for an SSL site when using a proxy. The CONNECT request is actually on port 80, and is an instruction to the proxy that it should connect to the site using port 443. The manual '&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://hostname:443"&gt;http://hostname:443&lt;/A&gt;&lt;SPAN&gt;' is not quite the same thing that the GP client will use.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A raw HTTP request on port 443 would look like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP Destination Port: 443&lt;/P&gt;&lt;P&gt;GET / HTTP\1.1&lt;BR /&gt;Host: hostname.example.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whereas the CONNECT would look like:&lt;/P&gt;&lt;P&gt;TCP Destination Port: 8080&lt;/P&gt;&lt;P&gt;CONNECT HTTPS://67.214.245.37:443/ HTTP\1.1&lt;BR /&gt;Host: hostname.example.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If your browser also uses a proxy, you can go to "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://67.214.245.37:443"&gt;https://67.214.245.37:443&lt;/A&gt;&lt;SPAN&gt;" and it should return valid data. A packet capture would show the CONNECT request from your browser as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Nov 2013 15:18:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/41479#M30506</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-11-29T15:18:44Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client behind a proxy, configuration help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/520604#M107889</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32522"&gt;@bigtone&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Two things:&lt;/P&gt;
&lt;P&gt;It is one thing for the client to be behind a web proxy:&lt;/P&gt;
&lt;P&gt;There it is only enough that at the Proxy config level, allow or bypass the URL and/or subdomain of global protect, example:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://yourpublicIPoryourpublicsubdomainortheoneyouuse/*" target="_blank" rel="noopener"&gt;https://yourpublicIPoryourpublicsubdomainortheoneyouuse/*&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://yourpublicIPoryourpublicsubdomainorwhicheveruses" target="_blank" rel="noopener"&gt;https://yourpublicIPoryourpublicsubdomainorwhicheveruses&lt;/A&gt; globalprotect/global-protect/*&lt;BR /&gt;&lt;A href="https://yourpublicIPoryourpublicsubdomainortheoneyouuse" target="_blank" rel="noopener"&gt;https://yourpublicIPoryourpublicsubdomainortheoneyouuse&lt;/A&gt; globalprotect/global-protect/login.esp&lt;/P&gt;
&lt;P&gt;Example: vpnglobalprotect.acme.com or la IP publica, si que usas la Ip publica y no un subdominio 200.200.200.200 por dar un ejemplo.&lt;/P&gt;
&lt;P&gt;Now if apart from the client be behind the proxy and at the same time behind Palo Alto itself.&lt;/P&gt;
&lt;P&gt;On Palo Alto you must configure a no NAT rule.&lt;/P&gt;
&lt;P&gt;A source zone rule, the internal zone(s), pointing to the external zone, untrust, the wan zone of the firewall and the public IP and/or FQDN subdomain of the firewall and not setting any type of translation, that is, no NAT and It will already allow you to connect to Global protect from the Internal network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you can check, at level App Portal Global protect config, the option:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Detect Proxy for Each Connection&lt;BR /&gt;(Windows only)&lt;BR /&gt;Select No to auto-detect the proxy for the portal connection and use that proxy for subsequent connections. Select Yes (default) to auto-detect the proxy at every connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 04:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-client-behind-a-proxy-configuration-help/m-p/520604#M107889</guid>
      <dc:creator>Metgatz</dc:creator>
      <dc:date>2022-11-08T04:39:24Z</dc:date>
    </item>
  </channel>
</rss>

