<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect and overlapping networks - is it a problem? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134774#M47388</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally, I would never use 192.168.1.0/24 or 192.168.2.0/24 as a business network because so many home routers use those networks and you will run into overlaps. In your case, the local route for network 192.168.1.0/24 of the remote computer will have precedence over the default&amp;nbsp;route 0.0.0.0/0, so the packet will not go through the VPN tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
    <pubDate>Wed, 28 Dec 2016 05:38:41 GMT</pubDate>
    <dc:creator>BenjAudy.MTL</dc:creator>
    <dc:date>2016-12-28T05:38:41Z</dc:date>
    <item>
      <title>GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134710#M47383</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I'm using GP since few years without any problem. Recently my colleagues complains abut situation when he can't established RDP connection. Local networks in their home is 192.168.1.x and my servers are on the same network 192.168.1.x -&lt;BR /&gt;That's their issue.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;In my opinion it's not a problem because GP install virtual adapter that's have network designed for GP in my scenario 172.16.1.x.&lt;BR /&gt;&lt;BR /&gt;I force also route 0.0.0.0/0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I tryed to find tech docs explained such situation but I can't find one. Could You point me in right directions of proofing my rights please.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 20:41:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134710#M47383</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2016-12-27T20:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134728#M47384</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do PCAP from the client when attempting connection to the RDP server. That will prove the source IP&amp;nbsp;you are coming from.&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is happening if they are not connected to the&amp;nbsp;GP, &amp;nbsp;can they RDP to the server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Myky&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2016 21:48:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134728#M47384</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-12-27T21:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134774#M47388</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Personally, I would never use 192.168.1.0/24 or 192.168.2.0/24 as a business network because so many home routers use those networks and you will run into overlaps. In your case, the local route for network 192.168.1.0/24 of the remote computer will have precedence over the default&amp;nbsp;route 0.0.0.0/0, so the packet will not go through the VPN tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 05:38:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134774#M47388</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-12-28T05:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134822#M47395</link>
      <description>&lt;P&gt;Hello Benjamin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know that in business we shouldn't use 192.168.1.x network - in my case this is historical - and very hard to change now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't do pcap right now, I will do that in few days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case I was able to ping any of my servers without problem. So are You sure that this is a route issue?&lt;/P&gt;&lt;P&gt;How to explain that ping was OK when RDP not?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 09:13:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134822#M47395</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2016-12-28T09:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134853#M47398</link>
      <description>&lt;P&gt;I imagine that the end user is utilizing a Windows box? Overlap on the VPN networks are well known to cause serious issues with routing on Windows due to it prioritizing known paths. Everyone can say that this really&amp;nbsp;&lt;EM&gt;shouldn't&amp;nbsp;&lt;/EM&gt;cause and issue, but it does for whatever reason even when running a 0.0.0.0/0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing that I would double check is if the end-user is properly initiating an RDP. If you can ping the server then it&amp;nbsp;&lt;EM&gt;should&lt;/EM&gt; be able to RDP as long as Windows isn't doing something funky in the background; are you sure that the user is properly logging into the server using the DOMAIN\user and the proper password?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 14:35:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134853#M47398</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-28T14:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134862#M47404</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Of course it's Windwos box &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I need to use 0.0.0.0/0 route because I need internet access from my IP's and access to local servers.&lt;/P&gt;&lt;P&gt;Is it other possibility to achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;route print from my Windows box:&lt;/P&gt;&lt;P&gt;IPv4 Route Table&lt;BR /&gt;===========================================================================&lt;BR /&gt;Active Routes:&lt;BR /&gt;Network Destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Netmask&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Gateway&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface&amp;nbsp; Metric&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.8.1&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.8.101&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; On-link&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.1.6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; xxx.xxx.xxx.xxx&amp;nbsp; 255.255.255.255&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.8.1&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.8.101&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 50&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as we can see link from 172.16.1.6 has "1" metric. I belive that routing table was the same from laptop that has issue. I know that I'm using 192.168.8.x network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will check this in lab with router with 192.168.1.0 network on 3th January.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user can not even logon because when he tryed to connect using mstsc.exe logon windows doesn't appear, only after about 60s popup with "cannot conect bla bla" appear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 15:21:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134862#M47404</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2016-12-28T15:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134865#M47406</link>
      <description>&lt;P&gt;You might just want to try and have him connect to the FQDN of the device; that's what we have all of our users do and we don't get any overlap issues. Generally that works alot better than simple IP connections.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 15:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134865#M47406</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-28T15:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134874#M47408</link>
      <description>&lt;P&gt;This was my first step, we tryed to conenct using IP address - so this problem was eliminated.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 16:19:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134874#M47408</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2016-12-28T16:19:26Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134927#M47415</link>
      <description>&lt;P&gt;The overlapping networks is ALWAYS a problem.. You have to either Exclude that network from the VPN OR you need to NAT. There is no way to easily avoid it when you have the overlap.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2016 22:55:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/134927#M47415</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2016-12-28T22:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/135362#M47502</link>
      <description>&lt;P&gt;Helllo&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank You all for replays.&lt;/P&gt;&lt;P&gt;I will do NAT for connections between laptops and servers on 192.168.1.x network. I prefer to not NAT on connection between laptop and other servers ie. 192.168.10.x.&lt;/P&gt;&lt;P&gt;I hope that this solve my problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2017 13:33:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/135362#M47502</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-01-02T13:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136046#M47584</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One more question&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to collect information about local user assigned IP addres from their home router? Please give me advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 21:52:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136046#M47584</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-01-05T21:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136051#M47585</link>
      <description>&lt;P&gt;The simplest way to get that information would be to get a "ipconfig" from a Dos window or Terminal window&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To get this:&lt;/P&gt;
&lt;P&gt;IPv4 Address. . . . . . . . . . . : 192.168.1.50&lt;BR /&gt; Subnet Mask . . . . . . . . . . . : 255.255.255.0&lt;BR /&gt; Default Gateway . . . . . . . . :192.168.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should tell you everything you need to know.. Network size, Gateway IP, etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2017 22:28:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136051#M47585</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2017-01-05T22:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136162#M47593</link>
      <description>&lt;P&gt;no no&lt;/P&gt;&lt;P&gt;I'd like to this on PA box using HIP profile....&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 11:08:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136162#M47593</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-01-06T11:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136211#M47607</link>
      <description>&lt;P&gt;I'm almost certain that you can't obtain this information using HIP check. The IP address is stored in the registry so you could potentially make sure that it isn't overlapping with your own network segment, but usually as long as your network isn't using 10.0.0.0/24 or 192.168.1.0/24 you shouldn't interlap with most home networks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 14:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136211#M47607</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-06T14:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect and overlapping networks - is it a problem?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136270#M47615</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm pretty sure that it's possible, please take a look&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-HIP-for-Missing-Microsoft-Patches/ta-p/52268" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-HIP-for-Missing-Microsoft-Patches/ta-p/52268&lt;/A&gt;&lt;/P&gt;&lt;P&gt;if we can check patch we can check confogurtion of interfaces - I believe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HIP.jpg" style="width: 741px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7178iC242B4C8EA1F1278/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="HIP.jpg" alt="HIP.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to do that - this is a question. I hope that someone will help me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2017 17:42:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-and-overlapping-networks-is-it-a-problem/m-p/136270#M47615</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2017-01-06T17:42:32Z</dc:date>
    </item>
  </channel>
</rss>

