<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple GlobalProtect Gateways on same interface? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234706#M67280</link>
    <description>&lt;P&gt;We recently (today) configured pre-logon VPN, but have come across what could be a show stopper. As its currently configured we have configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway &amp;gt; (gateway name) &amp;gt; Authentication &amp;gt; Certificate Profile &amp;gt; (a client cert signed by our infrastructure)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If a machine has this cert installed it now succesfully connects via "pre-logon", and once signed into Windows it all works as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If a machine doesnt have this cert installed then "pre-logon" does not work, but additionally they are unable to sign in once in Windows as they are presented with an error stating cert is missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this how it should be configured or have i missed a step somewhere?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is we have a requirement for some non-domain users/assets to be able to connect to the VPN. As it stands with the way i have configured pre-logon they cant connect, as the cert is missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the correct way to resolve this and keep pre-logon?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking to create a second gateway, on the same interface as the current one, but assign a secondary IP to the interface. I would more or less copy the config from the existing gateway, but not assign a certificate profile to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The portal agent config for these external users would then be configured to use the newly created gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this how to solve this problem?&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2018 09:26:45 GMT</pubDate>
    <dc:creator>welly_59</dc:creator>
    <dc:date>2018-10-10T09:26:45Z</dc:date>
    <item>
      <title>Multiple GlobalProtect Gateways on same interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234706#M67280</link>
      <description>&lt;P&gt;We recently (today) configured pre-logon VPN, but have come across what could be a show stopper. As its currently configured we have configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway &amp;gt; (gateway name) &amp;gt; Authentication &amp;gt; Certificate Profile &amp;gt; (a client cert signed by our infrastructure)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If a machine has this cert installed it now succesfully connects via "pre-logon", and once signed into Windows it all works as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If a machine doesnt have this cert installed then "pre-logon" does not work, but additionally they are unable to sign in once in Windows as they are presented with an error stating cert is missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this how it should be configured or have i missed a step somewhere?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is we have a requirement for some non-domain users/assets to be able to connect to the VPN. As it stands with the way i have configured pre-logon they cant connect, as the cert is missing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the correct way to resolve this and keep pre-logon?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking to create a second gateway, on the same interface as the current one, but assign a secondary IP to the interface. I would more or less copy the config from the existing gateway, but not assign a certificate profile to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The portal agent config for these external users would then be configured to use the newly created gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this how to solve this problem?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 09:26:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234706#M67280</guid>
      <dc:creator>welly_59</dc:creator>
      <dc:date>2018-10-10T09:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple GlobalProtect Gateways on same interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234754#M67289</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91200"&gt;@welly_59&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the correct way to resolve this and keep pre-logon?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was thinking to create a second gateway, on the same interface as the current one, but assign a secondary IP to the interface. I would more or less copy the config from the existing gateway, but not assign a certificate profile to it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The portal agent config for these external users would then be configured to use the newly created gateway.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this how to solve this problem?&lt;/STRONG&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should work.&amp;nbsp; This is what I was thinking as well.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 12:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234754#M67289</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-10-10T12:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple GlobalProtect Gateways on same interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234768#M67294</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/91200"&gt;@welly_59&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;mentioned this would work perfectly fine and accomplish exactly what you are looking to do without issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 13:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234768#M67294</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-10-10T13:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple GlobalProtect Gateways on same interface?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234779#M67299</link>
      <description>&lt;P&gt;Excellent news. While waiting for an answer here though ihave succesfuly configured it using a loopback interface on the FW (public IP on it, we have loads), and it all works&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2018 13:50:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-globalprotect-gateways-on-same-interface/m-p/234779#M67299</guid>
      <dc:creator>welly_59</dc:creator>
      <dc:date>2018-10-10T13:50:58Z</dc:date>
    </item>
  </channel>
</rss>

