<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2 Different remote VPN connect methods on a single portal&amp;amp;single gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248601#M70714</link>
    <description>&lt;P&gt;I am trying to configure always-on with&amp;nbsp;LDAP authentication for my internal users, meaning my users should connect to the network with their AD creds as soon as they go outside. At the same time, my contractors should use RADIUS for on-demand.&lt;/P&gt;</description>
    <pubDate>Sat, 02 Feb 2019 17:53:13 GMT</pubDate>
    <dc:creator>SThatipelly</dc:creator>
    <dc:date>2019-02-02T17:53:13Z</dc:date>
    <item>
      <title>2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248458#M70658</link>
      <description>&lt;P&gt;I have external contractors connecting to my GP Portal in an on-demand connection setup.&lt;/P&gt;&lt;P&gt;Is it possible to enable 'always-on' VPN on same portal and gateway pair alongside with on-demand?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 13:43:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248458#M70658</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-02-01T13:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248494#M70667</link>
      <description>&lt;P&gt;Yes it is, i have several options on the same portal, some are on demand, some are always on and others include manual gateway selections and the option to disable GP. Just do it by users or users group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;at the very bottom of my list i have a default one.... this may be best to use for anybody who connects but put your configs for users and groups above the default as they will use the first that applies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;post again if you require any further infi...&lt;/P&gt;</description>
      <pubDate>Fri, 01 Feb 2019 16:54:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248494#M70667</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-01T16:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248591#M70710</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;Thank you so much for your response.&lt;/P&gt;&lt;P&gt;I have a RADIUS authentication method setup for contractors today for on-demand. I can't think of having my internal users using always-on without having to go through RADIUS authentication at the same time my contractors using RADIUS.&lt;/P&gt;&lt;P&gt;can you please provide me any ideas how to accomplish this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 17:25:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248591#M70710</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-02-02T17:25:13Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248599#M70712</link>
      <description>&lt;P&gt;Sorry&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;, i dont understand what you are asking,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that your contractors are on demand with radius but not sure what you need for internal users.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 17:32:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248599#M70712</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-02T17:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248600#M70713</link>
      <description>&lt;P&gt;What authentication method do your internal users have.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 17:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248600#M70713</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-02T17:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248601#M70714</link>
      <description>&lt;P&gt;I am trying to configure always-on with&amp;nbsp;LDAP authentication for my internal users, meaning my users should connect to the network with their AD creds as soon as they go outside. At the same time, my contractors should use RADIUS for on-demand.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 17:53:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248601#M70714</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-02-02T17:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248603#M70716</link>
      <description>&lt;P&gt;Yes you can do this but i have never tried it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you need to set up an authentication sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have more internal users than contractors put ldap first, if more contractors than internal users then radius first.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then place this in the authentication section of the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then on the agent section... &amp;nbsp; add a config called contractors, add each of the contractors login id. Set the app here to on demand&lt;/P&gt;&lt;P&gt;then add a config called default. Leave the users blank, set this app to always on, plus any other options needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for both , set authentication overide, also allow this on the gateway. Then they can both share the same gateway also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do as much as you can, if you get stuck i will go into greater detail but get the authentication sequence working first.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 18:12:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248603#M70716</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-02T18:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248604#M70717</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;Sure. But, before doing it, I justhave&amp;nbsp; couple of final questions(As it is on production firewall, I'm trying to gather as much info as I can). My cuurent setup has RADIUS for gateway authentication. As I am doing the auth override on portal, should I be least worried about this tab on gateway?&lt;/P&gt;&lt;P&gt;Am I correct in assuming that keeping the current config on GAteway as is but&amp;nbsp;adding new&amp;nbsp;"client settings" config(Diff pool for internal users) will work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you so much.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 18:49:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248604#M70717</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-02-02T18:49:32Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248612#M70719</link>
      <description>&lt;P&gt;Im not sure what you are asking, if it helps... you can have auth overide and radius on gateway. If the user does not have auth overide cookie then it will fall back to radius.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you cannot afford to mess up your config, why not set up a loopback address and test on that.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 19:56:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248612#M70719</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-02T19:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248613#M70720</link>
      <description>&lt;P&gt;Also... you dont have to use auth overide.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you have auth sequence in portal then just have the same auth sequence in gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i just prefer overide... especially for OTP.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Feb 2019 20:07:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248613#M70720</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-02-02T20:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Different remote VPN connect methods on a single portal&amp;single gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248728#M70752</link>
      <description>&lt;P&gt;thank you. I'll try it and keep you updated with the result.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Feb 2019 14:26:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/2-different-remote-vpn-connect-methods-on-a-single-portal-amp/m-p/248728#M70752</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-02-04T14:26:39Z</dc:date>
    </item>
  </channel>
</rss>

