<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: loopback for globalprotect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/214436#M62311</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I assume it allows you to add more virtual interfaces to one physical interface. I had read something that wa using a physical outside interface for their VPN. I guess thats okay if you only have one VPN and can spare a whole interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks reaper you helped me decide that for me created the new VPN on a loopback make more sense than assigning a whole interface to the outside to it&lt;/P&gt;</description>
    <pubDate>Wed, 16 May 2018 13:17:01 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2018-05-16T13:17:01Z</dc:date>
    <item>
      <title>loopback for globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/214344#M62296</link>
      <description>&lt;P&gt;What is the advantage of using a loopback interface for a global protect VPN?&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 19:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/214344#M62296</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-05-15T19:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: loopback for globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/214353#M62297</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;-It allows you to pick a different IP than the one that's attached to the physical interface (no need to fuss with subnetting etc)&lt;/P&gt;
&lt;P&gt;-It also provides a layer of protection, since you're able to create a security policy for &amp;lt;untrust to untrust, destination IP of the loopback&amp;gt;, that will actually protect against a few potential exploits (some zero-day web-targetted exploits could theoretically go unblocked by a threat prevention profile if the GP gateway is &lt;EM&gt;on&lt;/EM&gt; the physical interface as it could hit before the profile is triggered)&lt;/P&gt;
&lt;P&gt;-it provides more clarity in 'topology', as the GP is running on it's own interface+ip&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you really really need it, it could run on&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;a different zone and&lt;/LI&gt;
&lt;LI&gt;a different internal IP range and go through NAT&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;although I would not recommend this, as it makes the deployment far more complex, but there could be a need to do so&lt;/P&gt;</description>
      <pubDate>Tue, 15 May 2018 20:42:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/214353#M62297</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-05-15T20:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: loopback for globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/214436#M62311</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I assume it allows you to add more virtual interfaces to one physical interface. I had read something that wa using a physical outside interface for their VPN. I guess thats okay if you only have one VPN and can spare a whole interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks reaper you helped me decide that for me created the new VPN on a loopback make more sense than assigning a whole interface to the outside to it&lt;/P&gt;</description>
      <pubDate>Wed, 16 May 2018 13:17:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/214436#M62311</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-05-16T13:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: loopback for globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/215256#M62473</link>
      <description>&lt;P&gt;On a GP Gateway box, using a loopback interface with a private IP address also let's you share a single public IP and just forward ports through as needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have this setup on one of our GP Gateway firewalls as there are 3 separate Gateways configured.&amp;nbsp; They all share the same public IP, but have separate private IPs on loopback interfaces.&amp;nbsp; There are NAT Policies in place to forward specific destination ports to each of the private IPs (using the standard GP port).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, in the GP Portal, we have it configured to send different users to different gateways, and have the port listed in the config there.&lt;/P&gt;</description>
      <pubDate>Wed, 23 May 2018 20:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/215256#M62473</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2018-05-23T20:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: loopback for globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/588149#M117292</link>
      <description>&lt;P&gt;&amp;nbsp;can someone provide a real KB link to configure GP with loopback interface?&lt;/P&gt;</description>
      <pubDate>Tue, 28 May 2024 21:48:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/588149#M117292</guid>
      <dc:creator>M.Alam277086</dc:creator>
      <dc:date>2024-05-28T21:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: loopback for globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/588230#M117296</link>
      <description>&lt;P&gt;LMGTFY: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKPCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKPCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 09:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/588230#M117296</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-05-29T09:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: loopback for globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/588267#M117302</link>
      <description>&lt;P&gt;Although you can use loopback for GlobalProtect I suggest not to.&lt;/P&gt;
&lt;P&gt;If you have multiple ISPs and need to DNAT different WAN IPs to single GlobalProtect portal/gateway IP then use DMZ interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Limitation of loopback interface is that you can't apply QoS to it.&lt;/P&gt;</description>
      <pubDate>Wed, 29 May 2024 14:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/loopback-for-globalprotect-vpn/m-p/588267#M117302</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-05-29T14:18:39Z</dc:date>
    </item>
  </channel>
</rss>

