<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: global protect multiple portal issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187236#M57006</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;. Hi..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Though you can set the portal&amp;nbsp;cookie to stay for a week on clients so they only need to connect to the portal once every 5-7 days&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this in the GP App config,&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2017 17:16:50 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-11-15T17:16:50Z</dc:date>
    <item>
      <title>global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187215#M57004</link>
      <description>&lt;P&gt;We want to configure Portal level redundancy in Global protect .If we bind 2 IPs of 2 different location firewalls to our portal address then how does clinent interpret the DNS resolution .after how much time client will try on another system&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 16:43:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187215#M57004</guid>
      <dc:creator>NIRAVK9</dc:creator>
      <dc:date>2017-11-15T16:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187226#M57005</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77294"&gt;@NIRAVK9&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would need a script to automatically modify the DNS record if the 1st site was to go down. You can poll the firewall to see if it is up/interface up using SNMP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Though you can set the portal&amp;nbsp;cookie to stay for a week on clients so they only need to connect to the portal once every 5-7 days, this is usually enough time to get the portal up and running again if it goes down (RMA/case with ISP etc.).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternatively you could look at GP in the cloud?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/products/innovations/globalprotect-cloud-service" target="_blank"&gt;https://www.paloaltonetworks.com/products/innovations/globalprotect-cloud-service&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 17:05:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187226#M57005</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-11-15T17:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187236#M57006</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;. Hi..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Though you can set the portal&amp;nbsp;cookie to stay for a week on clients so they only need to connect to the portal once every 5-7 days&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this in the GP App config,&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 17:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187236#M57006</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-15T17:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187435#M57024</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;thankyou for the response. Whwre can i find the cookie setting?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if i map 2 IPs to portal address,then whether GP client will try to both Ips one by one ??&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 09:34:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187435#M57024</guid>
      <dc:creator>NIRAVK9</dc:creator>
      <dc:date>2017-11-16T09:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187439#M57026</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it is in the GP app config, in the GP portal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12480iA04C98783FBBB6CE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77294"&gt;@NIRAVK9&lt;/a&gt;&amp;nbsp;I'm not sure on this one as I have never done it myself as I've never needed portal redundancy due the above cookie authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A solution may be to allow users to change the portal address and use different portals but the same gateways. GP should connect to the gateway that responds first.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled2.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12481i354900E526A1D047/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Untitled2.png" alt="Untitled2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 09:49:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187439#M57026</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-11-16T09:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187441#M57028</link>
      <description>&lt;P&gt;if DNS resolves to 2 ip addresses your globalprotect client will only recieve 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if the portal connection fails then nothing else will happen.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you reconnect GP then it may get the same address or it may get the second address. it's pretty random and probably not a good idea to use this for redundancy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is known as DNS "round robin"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would still like to know also about the cookie setting.&amp;nbsp; where is it...&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 09:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187441#M57028</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-16T09:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187442#M57029</link>
      <description>&lt;P&gt;sorry &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;, just posted after you...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 09:57:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187442#M57029</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-16T09:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187443#M57030</link>
      <description>&lt;P&gt;BUt isn't this cookie only for authnetication prupose.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or the cookie also saves the gateways sent to client&amp;nbsp; during previous connect to portal?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187443#M57030</guid>
      <dc:creator>NIRAVK9</dc:creator>
      <dc:date>2017-11-16T10:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187444#M57031</link>
      <description>&lt;P&gt;cookie authentication.,,,,,,,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i dont think "cookie auth" answers your question but if you use GP with portal auth only that generates a cookie for the gateway auth then you will need to extend this for when your portal fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i don't think the cached portal ever expires. i only say this because i cannot see any info/help/advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;somebody else can jump in if they can advise further.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:10:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187444#M57031</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-16T10:10:31Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187445#M57032</link>
      <description>&lt;P&gt;Thankyou&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to make my question more clearer&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What i am looking for is&amp;nbsp; that when my primary portal fails/goes down&amp;nbsp; then&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) whether client still try to get the gateway from its cache and connect to one of the gateway which was given to it when it last conencted to portal&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) whether thwere is any way at DNS provider end that i can change the IP mapped to portal address to my secondary location address&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187445#M57032</guid>
      <dc:creator>NIRAVK9</dc:creator>
      <dc:date>2017-11-16T10:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187447#M57033</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77294"&gt;@NIRAVK9&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1) whether client still try to get the gateway from its cache and connect to one of the gateway which was given to it when it last conencted to portal&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2) whether thwere is any way at DNS provider end that i can change the IP mapped to portal address to my secondary location address&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes. we have access tou our DNS records and can change them any time. this will depend on your provider. you may have to call/log a call with them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please note that it will not be an immediate change. DNS replication is quite fast these days but it could take up to 24 hours to fully replicate across www.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187447#M57033</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-16T10:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187449#M57034</link>
      <description>&lt;P&gt;1) so for first is there ant way i can see where is this cache stored in users machine and how long it will be there?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187449#M57034</guid>
      <dc:creator>NIRAVK9</dc:creator>
      <dc:date>2017-11-16T10:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187450#M57035</link>
      <description>&lt;P&gt;i have no idea, i doubt you will be able to see it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:49:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187450#M57035</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-16T10:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: global protect multiple portal issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187451#M57036</link>
      <description>&lt;P&gt;in you host file within windows you could try to add your portal to a non existent address. try to connect GP and check to see what it says in the logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i've only ever seen "using cached portal" but there may be other info...&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2017 10:51:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-multiple-portal-issue/m-p/187451#M57036</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-16T10:51:48Z</dc:date>
    </item>
  </channel>
</rss>

