<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two Subnets For Two Group Of People in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118923#M45693</link>
    <description>&lt;P&gt;Hi Mikelanni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My advice would be to follow these steps in the troubleshooting guide for the private IP address assign issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check if the IP address pool has enough IPs&lt;BR /&gt;Check if the IP pool does not overlaps with the IP of the Client PC.&lt;BR /&gt;Check if the User Group used in Global Protect -&amp;gt; gateway -&amp;gt; Client Configuration -&amp;gt; Network Setting is properly included in the Group Mappings on the firewall and firewall is able to fetch the group from the AD server.&lt;BR /&gt;Check if the user belongs to the correct group as mentioned in the Network Settings of Client Configuration under GP gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-GlobalProtect/ta-p/75770" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-GlobalProtect/ta-p/75770&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally check the 'remote users' part in the info section of the GP gateways and disconnect any existing sessions from your user that you may have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your authentication profile is likely set up to include the domain field during authentication, so that is why the format 'domain\first.last' is failing when you try this as the firewall would see it as 'domain\domain\first.last'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you still have trouble after trying this then it would need a deeper look so might be worth raising a support ticket.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Tue, 11 Oct 2016 16:23:21 GMT</pubDate>
    <dc:creator>bmorris1</dc:creator>
    <dc:date>2016-10-11T16:23:21Z</dc:date>
    <item>
      <title>Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118782#M45673</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can one help me how to configure two groups of people that use GP as a VPN client?&lt;/P&gt;&lt;P&gt;let say I have user 1-5 needs to access my inside firewall with subnet 192.168.1.0/24&lt;/P&gt;&lt;P&gt;and I have users 6-10 needs to access my inside and couple of the IPsec tunnel to reach &amp;nbsp;inside of other firewalls with subnet 192.168.2.0/24&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to do it by multiple&amp;nbsp;gateways or any other way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PANOS 7.14h2&lt;/P&gt;&lt;P&gt;GP 3.1.1&lt;/P&gt;&lt;P&gt;no local user database&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2016 15:12:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118782#M45673</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-10-10T15:12:58Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118865#M45686</link>
      <description>&lt;P&gt;Hi Mikelanni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes you can do this by navigating to your GP gateway configuration and in the agent menu:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline"&gt;&lt;img /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_9.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5850iAAC9180478627D8A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_9.png" alt="Screenshot_9.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;In the client settings tab you can add a seperate client setting for your different user groups which you can configure them to have different subnets/access routes etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 15:35:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118865#M45686</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-10-11T15:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118895#M45690</link>
      <description>&lt;P&gt;I tried that with LDAP group but never works (no idea why and I don't recall the error i got it from GP client&amp;nbsp;need to test again and check what was the error) looks it not get the users from the group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;also do you give VPN users&amp;nbsp;same subnet to your inside networks? as I always give them another subnet&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 14:23:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118895#M45690</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-10-11T14:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118906#M45691</link>
      <description>&lt;P&gt;Hi Mikealanni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In that case it would be worth taking a look at your group mapping settings and making sure your users are mapped to the groups correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The configuration info on group mapping can be found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/map-users-to-groups#74222" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/map-users-to-groups#74222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally there is a nice guide on how to troubleshoot the various aspects of user-id here, you would need to use the CLI to check what users are mapped to which groups:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-User-ID-Group-and-User-to-IP-Mapping/ta-p/59072" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-User-ID-Group-and-User-to-IP-Mapping/ta-p/59072&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CLI command to show user and their group mapping info:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show user user-ids&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Filter it down to a single user:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show user user-ids match-user (user name)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually you would want your GP VPN users in seperate subnets as the local network to avoid any layer 2 issues, the screenshot was a bit hurried by me. I will modify it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 15:11:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118906#M45691</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-10-11T15:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118909#M45692</link>
      <description>&lt;P&gt;Firewall group working and I can see my users ( &lt;SPAN&gt;show user user-ids)&amp;nbsp;&lt;/SPAN&gt;in format&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;domain\first.last&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if I used that format in GP client I got error authentication&amp;nbsp;failed&amp;nbsp;but If I use first.last format only I&amp;nbsp;got assign private ip failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is what it showing in my group map&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;domain\mike.alani vsys1 cn=vpnadmin,ou=groups,ou=XXX,ou=services,ou=xxxx,dc=domain,dc=xxx,dc=xxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just changed couple info with xxx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is so far what I've found&lt;/P&gt;&lt;P&gt;if I configure my GP client setting with first.last and the GP&amp;nbsp;VPN client as first.last then it will connect&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with domain\first.last (as Palo alto drop list showing) and the GP&amp;nbsp;client as first.last then it will not connect and give me error assign private IP failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with domain\first.last and the GP&amp;nbsp;client as domain\first.last then it will not connect and give me error&amp;nbsp;authentication failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with group and the GP&amp;nbsp;client as first.last then it will not connect and give me error assign private IP failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with group and the GP&amp;nbsp;client as domain\first.last then it will not connect and give me error assign private IP failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 16:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118909#M45692</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-10-11T16:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118923#M45693</link>
      <description>&lt;P&gt;Hi Mikelanni,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My advice would be to follow these steps in the troubleshooting guide for the private IP address assign issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check if the IP address pool has enough IPs&lt;BR /&gt;Check if the IP pool does not overlaps with the IP of the Client PC.&lt;BR /&gt;Check if the User Group used in Global Protect -&amp;gt; gateway -&amp;gt; Client Configuration -&amp;gt; Network Setting is properly included in the Group Mappings on the firewall and firewall is able to fetch the group from the AD server.&lt;BR /&gt;Check if the user belongs to the correct group as mentioned in the Network Settings of Client Configuration under GP gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-GlobalProtect/ta-p/75770" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-GlobalProtect/ta-p/75770&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Additionally check the 'remote users' part in the info section of the GP gateways and disconnect any existing sessions from your user that you may have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your authentication profile is likely set up to include the domain field during authentication, so that is why the format 'domain\first.last' is failing when you try this as the firewall would see it as 'domain\domain\first.last'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you still have trouble after trying this then it would need a deeper look so might be worth raising a support ticket.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 16:23:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118923#M45693</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-10-11T16:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118925#M45694</link>
      <description>&lt;P&gt;Here is so far what I've found&lt;/P&gt;&lt;P&gt;if I configure my GP client setting with first.last and the GP&amp;nbsp;VPN client as first.last then it will connect&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with domain\first.last (as Palo alto drop list showing) and the GP&amp;nbsp;client as first.last then it will not connect and give me error assign private IP failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with domain\first.last and the GP&amp;nbsp;client as domain\first.last then it will not connect and give me error&amp;nbsp;authentication failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with group and the GP&amp;nbsp;client as first.last then it will not connect and give me error assign private IP failed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if I configure my GP client setting with group and the GP&amp;nbsp;client as domain\first.last then it will not connect and give me error assign private IP failed&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2016 16:30:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/118925#M45694</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-10-11T16:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/119098#M45751</link>
      <description>&lt;P&gt;found what was the error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried couple users with their&amp;nbsp;machines and it was working but my desktop was not then I figured out that when I capitalize&amp;nbsp;my first letter from mike to Mike that made the GP connect and no error.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&amp;nbsp;weird&amp;nbsp;thing is when I use mike in another laptop it is working &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 17:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/119098#M45751</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-10-13T17:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Two Subnets For Two Group Of People</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/120345#M45901</link>
      <description>&lt;P&gt;ok, solve this issue&lt;/P&gt;&lt;P&gt;first I figured that my desktop if I use mike.alani it will not match the LDAP group but If I used Mike.alani then it will match (other computers have not face this issue)&lt;/P&gt;&lt;P&gt;upgrading the firewall to 7.1.5 solve the issue with my desktop!!!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 20:55:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/two-subnets-for-two-group-of-people/m-p/120345#M45901</guid>
      <dc:creator>mikealanni</dc:creator>
      <dc:date>2016-10-20T20:55:28Z</dc:date>
    </item>
  </channel>
</rss>

