<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PPPOE interface - dynamic IP - GP Portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246578#M70200</link>
    <description>&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you select your ip where none is listed in GP portal configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the assumption pppoe differs from dhcp&lt;/P&gt;</description>
    <pubDate>Fri, 18 Jan 2019 09:37:56 GMT</pubDate>
    <dc:creator>pan219</dc:creator>
    <dc:date>2019-01-18T09:37:56Z</dc:date>
    <item>
      <title>PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246552#M70195</link>
      <description>&lt;P&gt;When establishing a connection via PPPOE there is no possibility to select the IP ("None") assigned by ISP in the Global Protect portal configuration, only the interface, which is not sufficient for it to work. I would expect that the IP assigned by ISP is created as an dynamic address object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2019-01-18 um 00.17.31.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18337iD07718D5431ECFDA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-01-18 um 00.17.31.png" alt="Bildschirmfoto 2019-01-18 um 00.17.31.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2019-01-18 um 00.17.08.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18338i24124C0ACB6D3498/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2019-01-18 um 00.17.08.png" alt="Bildschirmfoto 2019-01-18 um 00.17.08.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To make GP work with portal &amp;amp; gateway, I had to create a loopback, then doing a NAT from the pppoe interface's (in my case eth1/1) ip:some other port not being 443 to the loopback:443. I had to create an additional address object where I manually had to put in the dynamic ip. I now have to amend this address object manually every time the interface ip changes. Am I missing something here or is it really this cumbersome using PPPOE?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems PAN is not that much interested in supporting PPPOE connections- besides this, there is also lack of vlan tagging support once the L3 interface has been set to PPPOE which many ISPs require and no option for a scheduled reconnection.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 01:03:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246552#M70195</guid>
      <dc:creator>pan219</dc:creator>
      <dc:date>2019-01-18T01:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246576#M70199</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This should be work with 'None' in IP address field.&lt;/P&gt;&lt;P&gt;Here is my testbed (sorry, mine is dhcp client - not pppoe)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="interface.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18342iAB3636CDC8641D49/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="interface.png" alt="interface.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With above interface, if I configure GP as below...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gpportal.png" style="width: 500px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18343iD2A167C1F9D4EC98/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="gpportal.png" alt="gpportal.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The device recognizes IP address which retrieved from ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin@PA-220&amp;gt; debug ssl-vpn global-protect-portal&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;portal : gptest&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;portal address IPv4 : 58.156.1xx.xxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;admin@PA-220&amp;gt; debug ssl-vpn global-protect-gateway&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;gateway : gptest&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;gateway address (IPv4 Only) : 58.156.1xx.xxx&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;admin@PA-220&amp;gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 08:43:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246576#M70199</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2019-01-18T08:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246578#M70200</link>
      <description>&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you select your ip where none is listed in GP portal configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have the assumption pppoe differs from dhcp&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 09:37:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246578#M70200</guid>
      <dc:creator>pan219</dc:creator>
      <dc:date>2019-01-18T09:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246756#M70257</link>
      <description>&lt;P&gt;No, if IP address grabed dynamically, it&amp;nbsp;is&amp;nbsp;not shown on the list.&lt;/P&gt;&lt;P&gt;(as I mentioned above, it works with 'None')&lt;/P&gt;&lt;P&gt;By the way, if you configure static-ip under pppoe setting, it shows IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 00:21:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/246756#M70257</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2019-01-21T00:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/458067#M101878</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;after having spent two whole days on the topic of getting the GP-gateway up and running to connect via androids native ipsec client on a PPPoE interface with dynamically assigned IP...I gave up... and can confirm:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.) 'cumbersome' is an euphemism&lt;/P&gt;&lt;P&gt;2.) the 'solution' presented herein does not work for scenarios with dynamically assigned IP via PPPoE&lt;/P&gt;&lt;P&gt;3.) selecting 'none' IP in GP-gatway config will not work in this scenario -&amp;gt; the paloalto PA220 (SW Ver. 10.1.4) will not respond to IKE traffic on the PPPoE interface (captured via a transparent linux bridge on respective WAN uplink)&lt;/P&gt;&lt;P&gt;4.) I also tried Pan219s trick with NATting the ipsec traffic to a loopback interface with a static IP on which the GP-portal would reside with the modification of using the FQDN destination object of my WANs DDNS address in my NAT-rules' 'original packet' section. Here I had the problem that the FQDN object was not reliably translated and suddenly reported that it had 'no value assigned'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After all I share the impression that paloalto really does not pay too much attention to these SOHO scenarios, i.e. the lack of VLAN support, the DDNS implementation (had to use a linux box behind the palo to update my DDNS provider with firewalls external address) and now the non-functional GP-portal.&lt;/P&gt;&lt;P&gt;I don't want to put another router in front of the palo just to get the GP-portal up and running.&lt;/P&gt;&lt;P&gt;How are chances to get above functionalities implemented/fixed? Or anybody around with some virtuos workaround?&lt;/P&gt;&lt;P&gt;Any help would be highly appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 20:52:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/458067#M101878</guid>
      <dc:creator>supergonzo74</dc:creator>
      <dc:date>2022-01-11T20:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/459326#M101986</link>
      <description>&lt;P&gt;Hi Supergonzo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after some fiddling and trial an error I found the solution. Initially I also tried the fqdn workaround you mentioned above, also no success. The breakthrough: Instead of using an address object limited to the assigned WAN IP I have created an address object with the ip range 0.0.0.0/0 which is used in any rules (NAT as well as Security Policy).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's the only change I have made to the original setup. Lo and behold, this configuration works flawlessly since 2 years.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 20:08:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/459326#M101986</guid>
      <dc:creator>pan219</dc:creator>
      <dc:date>2022-01-18T20:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/460448#M102073</link>
      <description>&lt;P&gt;Hi Pan219,&lt;/P&gt;&lt;P&gt;tried the setup you mentioned above with the 0.0.0.0/0 object this evening but to no avail. When trying to commit my nat ruleset it throws following error as host portion of original address differs from translated when nat-ting from "0.0.0.0/0" to "loopback-ip/32":&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Error: nat rule 'inbound_ipsec_to_untrust_interface': Mismatch of destination address translation range between original address and translated address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you plz post a screenshot of your nat rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx in advance!&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2022 20:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/460448#M102073</guid>
      <dc:creator>supergonzo74</dc:creator>
      <dc:date>2022-01-23T20:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: PPPOE interface - dynamic IP - GP Portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/460866#M102118</link>
      <description>&lt;P&gt;some more clarification:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I have limited the source address: x.x.x.x/x&lt;/P&gt;&lt;P&gt;- the loopback ip is an address object in the format x.x.x.x&amp;nbsp; without the /32&lt;/P&gt;&lt;P&gt;- gateway and portal sitting on the loopback interface&lt;/P&gt;&lt;P&gt;- in gateway configuration - agents - tunnel settings: tunnel mode and ipsec is enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Bildschirmfoto 2022-01-25 um 10.26.19.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38764iE9B8A3D103910144/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Bildschirmfoto 2022-01-25 um 10.26.19.png" alt="Bildschirmfoto 2022-01-25 um 10.26.19.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jan 2022 10:01:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pppoe-interface-dynamic-ip-gp-portal/m-p/460866#M102118</guid>
      <dc:creator>pan219</dc:creator>
      <dc:date>2022-01-25T10:01:34Z</dc:date>
    </item>
  </channel>
</rss>

