<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Number of supported Global Protect clients per box ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43069#M31598</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In all the specifications sheets there is a different number listed for the concurrent SSLVPN and IPSECVPN supported clients. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg. on a 5020 &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;2,000 IPSec VPN tunnels/tunnel interfaces&lt;/LI&gt;&lt;LI&gt;5,000 SSL VPN Users&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find these number very confusing :&lt;/P&gt;&lt;P&gt;Globalprotect uses both IPSEC and SSL ( IPSEC is preferred I was told).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question, how many globalprotect clients are supported then on, for example , a 5020 ? 2000 or 5000 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Feb 2013 14:18:43 GMT</pubDate>
    <dc:creator>Bart_Jocque</dc:creator>
    <dc:date>2013-02-05T14:18:43Z</dc:date>
    <item>
      <title>Number of supported Global Protect clients per box ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43069#M31598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In all the specifications sheets there is a different number listed for the concurrent SSLVPN and IPSECVPN supported clients. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg. on a 5020 &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;2,000 IPSec VPN tunnels/tunnel interfaces&lt;/LI&gt;&lt;LI&gt;5,000 SSL VPN Users&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I find these number very confusing :&lt;/P&gt;&lt;P&gt;Globalprotect uses both IPSEC and SSL ( IPSEC is preferred I was told).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question, how many globalprotect clients are supported then on, for example , a 5020 ? 2000 or 5000 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 14:18:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43069#M31598</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2013-02-05T14:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Number of supported Global Protect clients per box ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43070#M31599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I understand it (and as I have seen it in my lab testing) the GlobalProtect client will opportunistically use EITHER IPsec or SSL, not both at the same time. I have my GlobalProtect "allow rules" in my policy set up in a way where I only allow SSL VPN (because that's specifically what I want to test), so when the client connects it uses SSL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do commits on my lab PA2050 it yells at me that I don't have an application dependency configured for the 'panos-global-protect' app, because I don't have the IPsec related protocols added, but it works fine and my client always uses SSL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would think that maintaining IPsec VPN tunnels incurs a higher overhead on the PA boxes versus SSL VPN (maybe they have an embedded SSL crypto card on the box?), hence the difference you see in the numbers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Personally I only want to use SSL VPN with GlobalPrtotect, and I want to have the ability for the client to refuse to connect if the certificate isn't signed by a legitimate certificate authority (to prevent SSL man-in-the-middle).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 14:27:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43070#M31599</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-02-05T14:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: Number of supported Global Protect clients per box ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43071#M31600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And as side question to this, how would Apple IOS clients be counterd, I guess as IPSEC clients&amp;nbsp; ? So would this mean 2000max on 5020 ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 14:30:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43071#M31600</guid>
      <dc:creator>Bart_Jocque</dc:creator>
      <dc:date>2013-02-05T14:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Number of supported Global Protect clients per box ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43072#M31601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, iOS clients are counted as IPsec clients, because they take advantage of the embedded Cisco IPsec client that is bundled in with iOS (we have VPN access for iOS clients deployed, so I have direct experience with this too).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 14:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/number-of-supported-global-protect-clients-per-box/m-p/43072#M31601</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-02-05T14:33:06Z</dc:date>
    </item>
  </channel>
</rss>

