<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP Server Update DHCP from GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-server-update-dhcp-from-globalprotect/m-p/66557#M39232</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;with v7 you can have GP to assign static ip's.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/globalprotect-features/static-ip-address-allocation.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/globalprotect-features/static-ip-address-allocation.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mean that after users connect to GP they have to join workstation computers to domain?&lt;/P&gt;
&lt;P&gt;Domain joined computers should update their DNS records correctly themselves so it should not be an issue after workstation is domain joined already.&lt;/P&gt;
&lt;P&gt;DNS server can be configured to trust DNS record updates from non domain joined computers aswell but if you configure this then anyone can spoof your dns records and not good idea &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Oct 2015 13:37:54 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2015-10-14T13:37:54Z</dc:date>
    <item>
      <title>LDAP Server Update DHCP from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-server-update-dhcp-from-globalprotect/m-p/66552#M39231</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you may know: &amp;nbsp;When a client is connected on&amp;nbsp;GlobalProtect, they are assigned a dynamic IPv4 Address, not static. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my situation, I have about 100 GlobalProtect clients. &amp;nbsp;When the client connects for the first time, they are required to join my domain (i.e. &lt;A href="http://www.contoso.com)." target="_blank"&gt;www.contoso.com).&lt;/A&gt; &amp;nbsp;My Domain Controller is behind my PA firewall. &amp;nbsp;The Domain Controller is also my LDAP server that is used for authenticating the GlobalProtect clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The purpose for connnecting to the domain controller is so we can remotely administer the devices connected on GlobalProtect using their fully qualified domain name (i.e. computer1.contoso.com) instead of having to look up their dynamic address from the firewall.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem: &amp;nbsp;Since the devices are assigned dynamic addresses, the IPv4 addresses are changing all the time. &amp;nbsp;Therefore, the DNS server (Domain Controller/LDAP server) has associated the correct domain name with an incorrect IPv4 address. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am assuming there is a way to update the records on hte domain controller to pull the correct dynamic addresses from the clients, just do not know if anyone has tried it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 13:20:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-server-update-dhcp-from-globalprotect/m-p/66552#M39231</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2015-10-14T13:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Server Update DHCP from GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-server-update-dhcp-from-globalprotect/m-p/66557#M39232</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;with v7 you can have GP to assign static ip's.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/globalprotect-features/static-ip-address-allocation.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/newfeaturesguide/globalprotect-features/static-ip-address-allocation.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you mean that after users connect to GP they have to join workstation computers to domain?&lt;/P&gt;
&lt;P&gt;Domain joined computers should update their DNS records correctly themselves so it should not be an issue after workstation is domain joined already.&lt;/P&gt;
&lt;P&gt;DNS server can be configured to trust DNS record updates from non domain joined computers aswell but if you configure this then anyone can spoof your dns records and not good idea &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2015 13:37:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-server-update-dhcp-from-globalprotect/m-p/66557#M39232</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2015-10-14T13:37:54Z</dc:date>
    </item>
  </channel>
</rss>

