<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Portal availability in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-availability/m-p/175276#M54947</link>
    <description>&lt;P&gt;Hello, &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a primary and secondary datacenter. &amp;nbsp;We have a Palo NGFW with Portal and GW configured at our primary DC and a second Palo NGFW configured as an additional GW at our secondary DC. &amp;nbsp;Portal configuration has both GW's setup with the primary datacenter GW as higher priority. &amp;nbsp;If the primary datacenter fails or access to the portal fails, will the existing clients with existing configurations just connect to the secondary datacenter? &amp;nbsp;I understand that the clients need to talk with the portal to get the initial configurations and specifically the list of GWs but after they have this, can the portal fail and they will just connect via the priority 2 GW without access to the portal? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the Portal is absolutely necessary for client connections each and every time (even if there are no updates to configuration), is there a better means to deal with a single portal and multiple GWs in different datacenters? &amp;nbsp;Or do i just default to setting up the secondary datacenter Palo NGFW as its own independant portal and gw and just use the same DNS name/cert and change DNS record in the case of a failure?&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2017 22:16:54 GMT</pubDate>
    <dc:creator>Baker1</dc:creator>
    <dc:date>2017-09-06T22:16:54Z</dc:date>
    <item>
      <title>GlobalProtect Portal availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-availability/m-p/175276#M54947</link>
      <description>&lt;P&gt;Hello, &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a primary and secondary datacenter. &amp;nbsp;We have a Palo NGFW with Portal and GW configured at our primary DC and a second Palo NGFW configured as an additional GW at our secondary DC. &amp;nbsp;Portal configuration has both GW's setup with the primary datacenter GW as higher priority. &amp;nbsp;If the primary datacenter fails or access to the portal fails, will the existing clients with existing configurations just connect to the secondary datacenter? &amp;nbsp;I understand that the clients need to talk with the portal to get the initial configurations and specifically the list of GWs but after they have this, can the portal fail and they will just connect via the priority 2 GW without access to the portal? &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the Portal is absolutely necessary for client connections each and every time (even if there are no updates to configuration), is there a better means to deal with a single portal and multiple GWs in different datacenters? &amp;nbsp;Or do i just default to setting up the secondary datacenter Palo NGFW as its own independant portal and gw and just use the same DNS name/cert and change DNS record in the case of a failure?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 22:16:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-availability/m-p/175276#M54947</guid>
      <dc:creator>Baker1</dc:creator>
      <dc:date>2017-09-06T22:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Portal availability</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-availability/m-p/175290#M54950</link>
      <description>&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-architecture/globalprotect-reference-architecture-features/monitoring-and-high-availability" target="_self"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-architecture/globalprotect-reference-architecture-features/monitoring-and-high-availability&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"...&lt;SPAN&gt;If the portal becomes unavailable, new users (who have never connected to the portal before) will not be able to connect to GlobalProtect. However, existing users can use the cached portal client configuration to connect to one of the gateways."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, if the portal fails, the clients still have a cached list of gateways where they can connect. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 22:40:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-portal-availability/m-p/175290#M54950</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-09-06T22:40:30Z</dc:date>
    </item>
  </channel>
</rss>

