<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205897#M60425</link>
    <description>&lt;P&gt;or maybe i misunderstood the post....&amp;nbsp;&amp;nbsp; sorry..&lt;/P&gt;</description>
    <pubDate>Fri, 16 Mar 2018 12:36:03 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-03-16T12:36:03Z</dc:date>
    <item>
      <title>GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205742#M60392</link>
      <description>&lt;P&gt;I have a working GlobalProtect setup right now using a single Portal on the district firewall, and a single Gateway on the firewall for the location I want to have access to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, these are using&amp;nbsp;dedicated public IPs that are not used for anything else, assigned to&amp;nbsp;the public interface of the&amp;nbsp;two firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I can't figure out from searching google, PA Discussions forum, and other resources is whether or not these need to be dedicated IPs used solely for the portal/gateway setup; or, if the IP can be shared with other services?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eventually, I'd like to have a separate Gateway setup on each school firewall to allow admin staff to be able to access their files, servers, printers remotely. But, we don't have 50-odd public IPs that can be dedicated to this (each site only has 5 public IPs, used for all their public resources, with DNAT policies setup for forwarding specific ports through to various systems).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I just use one of the server IPs for the Gateway?&amp;nbsp; Or will that break things for the server and/or GlobalProtect?&amp;nbsp; Are there any Security Policy or NAT Policy changes needed to make that work?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 18:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205742#M60392</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-15T18:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205756#M60394</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42838"&gt;@fjwcash&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why don't you simply use the IP of the external interface for the Global Protect Gateway?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 19:42:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205756#M60394</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-15T19:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205767#M60398</link>
      <description>&lt;P&gt;Uhm ... uh ... er ... huh.&amp;nbsp; Because that never occurred to me?&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&amp;nbsp;I'll have to play with that, to make sure it doesn't interfere with management connections (we use that IP for the web management IP from within the district).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was testing a config with it set to "share" the IP of a server with existing NAT/Security Policies, and it tries to pass the GP SSL traffic through the NAT rule instead of terminating it on the firewall.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 20:23:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205767#M60398</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-15T20:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205896#M60424</link>
      <description>&lt;P&gt;Loopback interface could assist here,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 12:34:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205896#M60424</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-16T12:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205897#M60425</link>
      <description>&lt;P&gt;or maybe i misunderstood the post....&amp;nbsp;&amp;nbsp; sorry..&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 12:36:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205897#M60425</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-16T12:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205973#M60462</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;Loopback interface could assist here,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-on-Loopback-Interface/ta-p/56866&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I read a similar article about how to make GlobalProtect accessible on a different port by using a loopback interface and NAT rules but it didn't click how that would help my setup until this morning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can create a loopback interface on the school firewall and use that as the IP for the GP Gateway on that firewall.&amp;nbsp; Then just create NAT rules that forward ports 443 and 4501 from a shared public IP to the local IP, with Security rules to allow the panos-global-protect, panos-web, and ssl applications through on that public IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or something along those lines.&amp;nbsp; That way, there's an IP on the firewall that the GP connection terminates at, instead of having the traffic forwarded through the firewall.&amp;nbsp; That was the step I was missing yesterday when testing it with the shared IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit:&amp;nbsp; this is the article I read yesterday:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-Page-to-be-Accessed-on-any/ta-p/53460" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-Page-to-be-Accessed-on-any/ta-p/53460&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 15:24:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205973#M60462</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-16T15:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205979#M60465</link>
      <description>&lt;P&gt;as another option... is it not possible to connect to some of the schools services on same ip but different ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then use nat to forward to the corresponding server on its correct port.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you may then just be able to free up an IP.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 15:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205979#M60465</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-16T15:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205984#M60467</link>
      <description>&lt;P&gt;We already do that.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; Most of the IPs are shared across multiple systems with DNAT port forwarding setup.&amp;nbsp; It's only the heating/DDC panel and VC units that get their own dedicated IPs.&amp;nbsp; We're very conservative in how we use our IPs ... but we're also very heavy into networking services, video conferencing, VoIP, etc.&amp;nbsp; It took a lot of work to get our public IP usage down to just 5&amp;nbsp;for an elementary school and 8 for a secondary school.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm going to play around with the loopback interface/IP and NAT/port forwarding.&amp;nbsp; That should do what I need.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Mar 2018 15:51:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/205984#M60467</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-16T15:51:01Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/207484#M60818</link>
      <description>&lt;P&gt;Using a private IP on a loopback interface, with port-forwarding NAT Policies using a shared public IP works.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just configured a school firewall in this fashion, and the GlobalProtect client on my Windows laptop authenticates correctly to the Portal, then to the new Gateway, and I get access to the LAN and to the Internet via the firewall at that location.&amp;nbsp; Required changing some of the existing NAT Policies (switch from bi-di rule to separate in/out rules), but everything is working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the pointers in the right direction.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 18:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/207484#M60818</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-03-26T18:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Gateway: can it share an IP used in NAT/Security Policies?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/386733#M90293</link>
      <description>&lt;P&gt;Hi there! I know this thread is older...but how do you create a DNAT for 4501 AND 443?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, I have gateway configured with x.x.x.x:7000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a DNAT that forwards 7000 to 443.&amp;nbsp; How do I get it working with 4501? reason I ask is because I want my tunnel to use IPSEC rather than SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 03:09:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-gateway-can-it-share-an-ip-used-in-nat-security/m-p/386733#M90293</guid>
      <dc:creator>dejesusv</dc:creator>
      <dc:date>2021-02-19T03:09:59Z</dc:date>
    </item>
  </channel>
</rss>

