<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assign Secondary Public IP address in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/177333#M55318</link>
    <description>&lt;P&gt;Hi Myasin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What might be a solution for you would be to created a loopback interface and assign it an IP. You can then add all your globalprotect (GP) configuration to this loopback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then with a destination NAT rule you can say that traffic for your 2nd public IP will be destination NAT to your loopback for access to the GP portal/gateway. The device will proxy ARP for the 2nd public IP configurated on the NAT rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These links to the documentation can explain more&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;proxy ARP:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-policy-rules#_60332" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-policy-rules#_60332&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP on loopback:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2017 13:24:52 GMT</pubDate>
    <dc:creator>bmorris1</dc:creator>
    <dc:date>2017-09-18T13:24:52Z</dc:date>
    <item>
      <title>Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/176864#M55244</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got a new internet connection through router, the firewall-router connection use private subnet, but I got a public subnet from provider which I will route to the firewall private IP.&lt;/P&gt;&lt;P&gt;Since I will configure SSL-VPN, then I have to assign the external firewall interface public IP address so users can access for SSL-VPN setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now can I configure a secondary IP address (public) for the external firewall interface (firewall-router link), so we can use this public IP for the SSL-VPN setup (is this secondary IP going to be reachable from internet, although the primary IP is private)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 17 Sep 2017 16:09:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/176864#M55244</guid>
      <dc:creator>myasin</dc:creator>
      <dc:date>2017-09-17T16:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/176877#M55246</link>
      <description>&lt;P&gt;I would love to have a crack at this but i just dont get it, perhaps post a doodle or hope someone cleverer than me is also unable to sleep.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Sep 2017 19:48:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/176877#M55246</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-17T19:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/177317#M55315</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70047"&gt;@myasin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Forgive me if I have any part of this wrong from your description; but essentially the ISP configured gear provided to you is the device that terminates the public IPs, and to get the connection to your Palo Alto you're simply assigning a NAT or a port-forwarding policy to your firewall's private IP right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would question whether or not you truly need to have that priavte subnet between your router and your firewall or if you could simply pass the IPs through the router directily to the firwall. Even a home grade router should have the ability to do an IP-Passthrough or Bridge mode that would assign the public IP address directly to the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the device in incapable of providing a public IP address directly to the firewall the SSL-VPN can be configured perfectly fine without the firewall having a true public IP address assigned to it as long as the IP-Passthrough or port-forwarding is setup correctly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 12:51:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/177317#M55315</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-09-18T12:51:50Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/177333#M55318</link>
      <description>&lt;P&gt;Hi Myasin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What might be a solution for you would be to created a loopback interface and assign it an IP. You can then add all your globalprotect (GP) configuration to this loopback.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then with a destination NAT rule you can say that traffic for your 2nd public IP will be destination NAT to your loopback for access to the GP portal/gateway. The device will proxy ARP for the 2nd public IP configurated on the NAT rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These links to the documentation can explain more&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;proxy ARP:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-policy-rules#_60332" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/networking/nat-policy-rules#_60332&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP on loopback:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 13:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/177333#M55318</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-09-18T13:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Assign Secondary Public IP address</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/177553#M55359</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I managed to configure the public subnet between the router and the firewall, as the customer was refusing change any paramters in the router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Sep 2017 10:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-secondary-public-ip-address/m-p/177553#M55359</guid>
      <dc:creator>myasin</dc:creator>
      <dc:date>2017-09-19T10:06:19Z</dc:date>
    </item>
  </channel>
</rss>

