<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBF with Dual ISP.  Once Enabled GlobalProtect Clients no longer can connect. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/222304#M63934</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46464"&gt;@blohrer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Unless you are advertizing the same range with both ISPs then I would do exactly what&amp;nbsp;@Retired Member&amp;nbsp;is recommending.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 14 Jul 2018 20:34:59 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-07-14T20:34:59Z</dc:date>
    <item>
      <title>PBF with Dual ISP.  Once Enabled GlobalProtect Clients no longer can connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/222258#M63927</link>
      <description>&lt;P&gt;We have setup a PBF to route traffic to a new ISP link we have in case our primary fails.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both ISP interfaces are in one virtual router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once we change the default route to the Backup ISP and enable the PBF to forward all traffic to the Primary unless it fails, users can no longer connect to our&amp;nbsp;GlobalProtect portal with the GlobalProtect client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it is because of the new default route pointing at the secondary ISP, but is there a route I can create to fix?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 17:24:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/222258#M63927</guid>
      <dc:creator>blohrer</dc:creator>
      <dc:date>2018-07-13T17:24:33Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with Dual ISP.  Once Enabled GlobalProtect Clients no longer can connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/222266#M63928</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;create 2 virtual routers with 2 seperate default gateways.That will be better. you can then create 2 different global protect 1 for main,1 for second isp.your Lan and isp1 will be at default, your isp2 will be at new virtual router.Then you will also add a LAN- next vr default vr route at new virtual router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can use pbf for main with monitor and 2nd pbf rule will route clients to isp2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 17:42:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/222266#M63928</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-07-13T17:42:06Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with Dual ISP.  Once Enabled GlobalProtect Clients no longer can connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/222304#M63934</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/46464"&gt;@blohrer&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Unless you are advertizing the same range with both ISPs then I would do exactly what&amp;nbsp;@Retired Member&amp;nbsp;is recommending.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Jul 2018 20:34:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/222304#M63934</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-07-14T20:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: PBF with Dual ISP.  Once Enabled GlobalProtect Clients no longer can connect.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/223263#M64167</link>
      <description>&lt;P&gt;The only thing I have tried as of yet, is to move the Global Protect Gateway and Portal to the ISP two connection.&amp;nbsp; When I did this, the clients could successfully connect.&amp;nbsp; The only problem I had at that point was that once connected, the users could not access the local network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The VPN is used by a small number of users.&amp;nbsp; The second ISP is only used to roll over for outbound access for internal users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a routing issue I am missing to allow the VPN to work on the second ISP?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 12:50:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pbf-with-dual-isp-once-enabled-globalprotect-clients-no-longer/m-p/223263#M64167</guid>
      <dc:creator>blohrer</dc:creator>
      <dc:date>2018-07-23T12:50:48Z</dc:date>
    </item>
  </channel>
</rss>

