<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect - To which ethernet interface?  WAN Facing? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235925#M67624</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I was able to get the login GP screen.&lt;/P&gt;&lt;P&gt;Gateway and Portal interface have been changed to the E1/1 Untrusted interface.&lt;/P&gt;&lt;P&gt;As my E/1/ inteface is DHCP the IP setting was left at none vs. an IP for the GP interace.&lt;/P&gt;&lt;P&gt;Now - working through authentication (AD/LDAP).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 Oct 2018 23:34:16 GMT</pubDate>
    <dc:creator>catrock</dc:creator>
    <dc:date>2018-10-17T23:34:16Z</dc:date>
    <item>
      <title>GlobalProtect - To which ethernet interface?  WAN Facing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235764#M67567</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;I am setting up GP on a small home office PA220 .&amp;nbsp; I have a single E 1/1 Untrusted L3 interface that is internet facing.&lt;/P&gt;&lt;P&gt;My logic tells me this interface should have the GP configured on it.&amp;nbsp; However, the documentation and video turtorials don't specifically outline that the GP needs to be on an internet facing interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have followed the configurations to a 'T' with my GP interface being Untrusted L3 E 1/8.&amp;nbsp; This E 1/8 interface has no physical ethernet cable connected to it, nor does it actually bind with anything other than the tunnel.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is:&amp;nbsp; Have I configure the GP properly and it should work by visiting my external IP address from an outside location?&amp;nbsp; I wouldn't think so - but....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If GP should actually be assigned to to the internet facing IP (E 1/1) - How would I go about doing so as it is already assigned?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks PA-LC for all your help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 14:46:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235764#M67567</guid>
      <dc:creator>catrock</dc:creator>
      <dc:date>2018-10-17T14:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - To which ethernet interface?  WAN Facing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235773#M67570</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98907"&gt;@catrock&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It really depends on what GlobalProtect setup you want, there are multiple.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. If you want remote access to your home office, where you would be connecting from externally (internet cafe etc) then both the GlobalProtect portal and gateway should reside on your Outside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. If you want GlobalProtect as an extra layer of security where you would be connecting to it from inside the network, you would configure a GlobalProtect gateway to terminate on your internal interface.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Edit:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Have I configure the GP properly and it should work by visiting my external IP address from an outside location?&amp;nbsp; I wouldn't think so - but...."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Correct. Once the GlobalProtect portal and gateway are configured against your outside interface, visiting the IP address (recommended to use an FQDN) will present you with the portal login page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"If GP should actually be assigned to to the internet facing IP (E 1/1) - How would I go about doing so as it is already assigned?"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you select the interface for the globalprotect portal/gateway terminates on, by default the "IPv4 Address" dropdown will be set to "None" but selecting the dropdown will allow you to chose the IPs that are set on that interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this answers your question, there's some useful docs on this too:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-gateways/globalprotect-gateway-concepts/types-of-gateways" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/globalprotect-gateways/globalprotect-gateway-concepts/types-of-gateways&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The below article covers scenario one. step 6 discusses configuring the gateway on the untrust interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/remote-access-vpn-authentication-profile" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/remote-access-vpn-authentication-profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The below article covers scenario two&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/globalprotect-multiple-gateway-configuration" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/globalprotect-multiple-gateway-configuration&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:20:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235773#M67570</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-17T15:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - To which ethernet interface?  WAN Facing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235791#M67574</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Do you have a policy that allows that traffic to the IP? I always put a DENY ALL polic at the bottom of my policy list and have it log so I know if things are getting blocked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:52:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235791#M67574</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-17T15:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - To which ethernet interface?  WAN Facing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235821#M67588</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks much for the response.&lt;/P&gt;&lt;P&gt;Option 1 - is what I am after.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have a dynamic IP frm my ISP.&amp;nbsp; This map to a host nmane using a DynDns agent running inside my lan/network.&amp;nbsp; *Looks like there's no DynDnS agent option to run directly on the PA220?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my reading on NAT'g- I do see where I will want to&amp;nbsp; assign the external facing interface the FQDN as well.&amp;nbsp; I have used the FQDN in my GP certificate as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 19:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235821#M67588</guid>
      <dc:creator>catrock</dc:creator>
      <dc:date>2018-10-17T19:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - To which ethernet interface?  WAN Facing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235825#M67591</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98907"&gt;@catrock&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You're correct that PAN doesn't support DynDNS - but that shouldn't be required. Things that would be needed:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A port forward on your ISP router to forward all tcp/443 requests to your PAN FW IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding NAT - you'll want to make sure that the inbound traffic to your GP portal isn't hitting your outbound NAT rule, it may be required to make a "No-NAT" rule to say if you're coming from external going to the IP of your untrust interface then do not nat it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see the logs of your attempts in the traffic logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may have to override the default intrazone&amp;nbsp;and interzone-default rules and enable logging at session end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 16:44:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235825#M67591</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-10-17T16:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - To which ethernet interface?  WAN Facing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235830#M67595</link>
      <description>&lt;P&gt;Greetings &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The default DENY is in place at the bottom - yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 17:00:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235830#M67595</guid>
      <dc:creator>catrock</dc:creator>
      <dc:date>2018-10-17T17:00:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - To which ethernet interface?  WAN Facing?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235925#M67624</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I was able to get the login GP screen.&lt;/P&gt;&lt;P&gt;Gateway and Portal interface have been changed to the E1/1 Untrusted interface.&lt;/P&gt;&lt;P&gt;As my E/1/ inteface is DHCP the IP setting was left at none vs. an IP for the GP interace.&lt;/P&gt;&lt;P&gt;Now - working through authentication (AD/LDAP).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 23:34:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-to-which-ethernet-interface-wan-facing/m-p/235925#M67624</guid>
      <dc:creator>catrock</dc:creator>
      <dc:date>2018-10-17T23:34:16Z</dc:date>
    </item>
  </channel>
</rss>

