<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 7.1.2 Unable to reach GlobalProtect portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139310#M48090</link>
    <description>&lt;P&gt;I think&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;&amp;nbsp;pretty much nailed the first things to look at and you'll likely find an error with where you have the tunnel as far as the security zone goes or something weird with your NAT policy. I would look at the tunnels security zone first, and then look at the NAT as I think it's actually more likely that you actually set your tunnel interface to your internal zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing that I might recommend is actually making a GlobalProtect zone. It makes creating access policies and the like a little bit easier if you are looking to lock down your VPN users access, and it helps keep it really simple as far as access rules go.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2017 13:36:00 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-01-25T13:36:00Z</dc:date>
    <item>
      <title>7.1.2 Unable to reach GlobalProtect portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139209#M48081</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to get the GlobalProtect piece of the FW to work, I followed word for word from the 7.1 admin guide and still no luck. &amp;nbsp;When I go to monitor I see the source coming from the external-untrust zone (which is correct), but the to zone shows (internal - trust). If I am reading this doc correctly, the VPN should terminate on the tunnel interface it makes you create right?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Page 157 -&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/framemaker/71/globalprotect/globalprotect-admin-guide.pdf" target="_blank"&gt;https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/framemaker/71/globalprotect/globalprotect-admin-guide.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7388i49B4D1B9B21EF268/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture1.PNG" alt="Capture1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/7389i9A227B4C8368E2E3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 21:46:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139209#M48081</guid>
      <dc:creator>digitaltrance</dc:creator>
      <dc:date>2017-01-24T21:46:24Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1.2 Unable to reach GlobalProtect portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139272#M48086</link>
      <description>&lt;P&gt;Hi Digitaltrance,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're trying to web browse to your global protect portal you would ideally host this on your external interface or on a loopback interface. The tunnel interface would be for when you are connecting to the GP VPN and establishing a tunnel rather than web browsing to the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To establish the connection you will need to first allow the external client to access the portal to authenticate then also allow the gateway authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As your log shows external to internal hitting the default interzone deny, rather than say external to external intrazone default allow then it looks like you may be accidentally&amp;nbsp;NATing your traffic destined to your portal to your internal zone? Or you have set up your GP portal for an interface in your internal zone rather than an external zone? As you don't have a policy to allow that I can see in your screenshots.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the detailed log view (spyglass on the left of the log) and you can see if your traffic is being NATed incorrectly in the destination panel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 09:45:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139272#M48086</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-01-25T09:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1.2 Unable to reach GlobalProtect portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139310#M48090</link>
      <description>&lt;P&gt;I think&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;&amp;nbsp;pretty much nailed the first things to look at and you'll likely find an error with where you have the tunnel as far as the security zone goes or something weird with your NAT policy. I would look at the tunnels security zone first, and then look at the NAT as I think it's actually more likely that you actually set your tunnel interface to your internal zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing that I might recommend is actually making a GlobalProtect zone. It makes creating access policies and the like a little bit easier if you are looking to lock down your VPN users access, and it helps keep it really simple as far as access rules go.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 13:36:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139310#M48090</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-01-25T13:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1.2 Unable to reach GlobalProtect portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139323#M48094</link>
      <description>&lt;P&gt;It was a bad NAT policy guys, thanks so much for the help. It is working now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i just need to figure out how to get the routing correct to get to the internet, I can only access internal devices over the VPN atm.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 13:52:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/139323#M48094</guid>
      <dc:creator>digitaltrance</dc:creator>
      <dc:date>2017-01-25T13:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: 7.1.2 Unable to reach GlobalProtect portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/143271#M48681</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52246"&gt;@digitaltrance&lt;/a&gt;, If everything else is working, you need to take a look at your access route for GlobalProtect.&lt;/P&gt;
&lt;P&gt;Check inside of the WebGUI &amp;gt; Network &amp;gt; GlobalProtect &amp;gt; Click configuration for a gateway &amp;gt; Agent tab &amp;gt; click on a config profile &amp;gt; Network Settings - Access route on the right hand side.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is where the GP client will get its "access route" in order to know where to go.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you only give it access to your internal network, then that is all it has access to.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want it to route all of its traffic over GP, then you can use a 0.0.0.0/0 network. But please be aware, that this can cause local access issues for the GP client.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Feb 2017 20:16:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/7-1-2-unable-to-reach-globalprotect-portal/m-p/143271#M48681</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2017-02-15T20:16:15Z</dc:date>
    </item>
  </channel>
</rss>

