<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query on GlobalProtect SSL VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-globalprotect-ssl-vpn/m-p/215844#M62558</link>
    <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there's no "clean" way to accomplish this since you're trying to share the same port between 2 services&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;one workaround is to enable the gateway on a loopback interface, then set up NAT to redirect a 'different' external port (eg. 5000) to 443 onto the loopback. that way your GP client will connect to the gateway via port 5000 which the firewall will NAT to 443 on the loopback&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;portal may only be accessible from LAN as you can't use the same trick for portal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="port 5000.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15324i82A5898AF3D2EE2F/image-size/large?v=v2&amp;amp;px=999" role="button" title="port 5000.png" alt="port 5000.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 30 May 2018 07:19:31 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-05-30T07:19:31Z</dc:date>
    <item>
      <title>Query on GlobalProtect SSL VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-globalprotect-ssl-vpn/m-p/215813#M62554</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’ve got a single public IP address, which is used for GlobalProtect SSL VPN. I also want use this single public IP address to allow inbound static NAT to a SSL web server on my LAN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using GP 4.0.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I do this, the GlobalProtect SSL VPN client stops working and starts redirecting the traffic to the SSL web server. Is there a way around this so that both the GlobalProtect SSL VPN client and SSL web server will work on a single public IP address without having to use a separate IP address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 02:55:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-globalprotect-ssl-vpn/m-p/215813#M62554</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2018-05-30T02:55:42Z</dc:date>
    </item>
    <item>
      <title>Re: Query on GlobalProtect SSL VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/query-on-globalprotect-ssl-vpn/m-p/215844#M62558</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45418"&gt;@Farzana&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;there's no "clean" way to accomplish this since you're trying to share the same port between 2 services&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;one workaround is to enable the gateway on a loopback interface, then set up NAT to redirect a 'different' external port (eg. 5000) to 443 onto the loopback. that way your GP client will connect to the gateway via port 5000 which the firewall will NAT to 443 on the loopback&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;portal may only be accessible from LAN as you can't use the same trick for portal&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="port 5000.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15324i82A5898AF3D2EE2F/image-size/large?v=v2&amp;amp;px=999" role="button" title="port 5000.png" alt="port 5000.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 May 2018 07:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/query-on-globalprotect-ssl-vpn/m-p/215844#M62558</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-05-30T07:19:31Z</dc:date>
    </item>
  </channel>
</rss>

