<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect issue with BGP routing configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-issue-with-bgp-routing-configuration/m-p/257507#M73043</link>
    <description>&lt;P&gt;Routing is the most common issue I see for this symptom.&amp;nbsp;Are you doing source-NAT for your GlobalProtect clients?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recall that the gateway config on the firewall defines the source IP pools for your clients, and assigns them based on that. If you are not doing NAT, then you'll just need to ensure that the networks you're trying to reach understand that they have to send the replies back to the firewall. If there's a more general/broad route on those networks' gateways, you'll need to use a more specific route for your GP clients source pool.&lt;/P&gt;</description>
    <pubDate>Fri, 12 Apr 2019 21:24:05 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2019-04-12T21:24:05Z</dc:date>
    <item>
      <title>Global Protect issue with BGP routing configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-issue-with-bgp-routing-configuration/m-p/257462#M73031</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured Global Protect and I can successfully connect. My Palo Altos are configured to peer and route via BGP which is working without issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is I cannot reach anything once I am connected. I need at access two address ranges. From the CLI of the Palo I can ping the gateways of the networks I need to reach via the GlobalProtect connections. I cannot ping when connected via global protect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I have noticed is that if I look at the more runtime stats in the virtual routers I can see the client pool subnet in the route table on interface Tunnel but not in the Forwarding table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 17:28:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-issue-with-bgp-routing-configuration/m-p/257462#M73031</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2019-04-12T17:28:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect issue with BGP routing configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-issue-with-bgp-routing-configuration/m-p/257507#M73043</link>
      <description>&lt;P&gt;Routing is the most common issue I see for this symptom.&amp;nbsp;Are you doing source-NAT for your GlobalProtect clients?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recall that the gateway config on the firewall defines the source IP pools for your clients, and assigns them based on that. If you are not doing NAT, then you'll just need to ensure that the networks you're trying to reach understand that they have to send the replies back to the firewall. If there's a more general/broad route on those networks' gateways, you'll need to use a more specific route for your GP clients source pool.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 21:24:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-issue-with-bgp-routing-configuration/m-p/257507#M73043</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-04-12T21:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect issue with BGP routing configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-issue-with-bgp-routing-configuration/m-p/257668#M73102</link>
      <description>&lt;P&gt;Thanks. After a weekend of looking I resolved this on the connecting router. It seems there was some diverse routing going on so the default gateway was pointing to another path. Once I removed this other path and tidied the config the expected default route displayed as expected and I had routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nothing as good as taking over someones configuration it seems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the advice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adrian&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 06:46:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-issue-with-bgp-routing-configuration/m-p/257668#M73102</guid>
      <dc:creator>a.jones</dc:creator>
      <dc:date>2019-04-16T06:46:49Z</dc:date>
    </item>
  </channel>
</rss>

