<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect setup frustration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289397#M76969</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;That was it guys!&amp;nbsp; Thanks again!&amp;nbsp; On to HIPS!!!&lt;/P&gt;</description>
    <pubDate>Fri, 20 Sep 2019 19:29:35 GMT</pubDate>
    <dc:creator>Shawverr</dc:creator>
    <dc:date>2019-09-20T19:29:35Z</dc:date>
    <item>
      <title>GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288845#M76887</link>
      <description>&lt;P&gt;Hello -&lt;/P&gt;&lt;P&gt;Originally, I was going to setup GP with RSA MFA using this document: "RSA SECURID® ACCESS Implementation Guide Palo Alto Networks Next Gen Firewall 8.0"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is written by RSA and is&amp;nbsp;woefully lacking in detail and after seven hours on the phone with Palo support I decided to abandon that idea for now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point I'd just like to get GP working in any capacity, but I can't seem to find any documentation that speak to what I need.&amp;nbsp; I understand that everyone's cirumstances are different and documentation would be tough to write for every unique situation.&amp;nbsp; That's why I'm hoping someone is willing to get out the coloring book and crayons to help walk me though this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'd like to have an external only VPN (just about every Google search come up with either Internal only or internal/external combo setups). Portal and gateway on same device.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm fairly certain that my main issue is with step one, the configuration of the Interface.&amp;nbsp; I'm trying to follow this:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html&lt;/A&gt;&amp;nbsp;but clearly not having much luck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ethernet Internet setup like this:&lt;/P&gt;&lt;P&gt;Interface&amp;nbsp; Type&amp;nbsp; Mgt Profile&amp;nbsp; &amp;nbsp;IP Address&amp;nbsp; &amp;nbsp; VR&amp;nbsp; &amp;nbsp;Security Zone&lt;/P&gt;&lt;P&gt;eth1/1&amp;nbsp; &amp;nbsp; &amp;nbsp; L3&amp;nbsp; &amp;nbsp; &amp;nbsp; Allow-ping&amp;nbsp; &amp;nbsp;Routable.10/24&amp;nbsp; &amp;nbsp;vr1&amp;nbsp; &amp;nbsp;Outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have another routable.20/32 for GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What's the best way to get started.&amp;nbsp; Remember, coloring book and crayons.&amp;nbsp; You're not going to offend me.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 18:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288845#M76887</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-17T18:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288877#M76891</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107987"&gt;@Shawverr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;So if you don't want to utilize your existing untrust (Outside) interface IP for this, and instead utilize a completely seperate address for your GP portal and gateway configuration, you would want to look at creating a loopback interface. Before you go down that route, can I ask why you don't just utilize the IP address already present on your untrust interface? If you are going to put the portal and gateway on the same address and not utilize a seperate interface for GP traffic, there really isn't a point in creating a completely seperate address for this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for an external only configuration, it isn't really touched on because it doesn't need to be. There isn't anything special you have to do, and most people actually run into more trouble configuring internal portals. You'll simply publish an external DNS record pointing towards whatever address you utilize, and then ensure that your internal users either can't resolve the portal address while on your internal network or are denied from connecting to the portal address while working from the internal network. You could also utilize internal host detection so that GP actually knows when it isn't needed to tunnel traffic back and not have to worry about it one way or another.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 04:21:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288877#M76891</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-18T04:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288931#M76899</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks for your reply.&amp;nbsp; The reason I don't want to use&amp;nbsp;&lt;SPAN&gt;utilize the IP address already present on my untrusted interface is because in the documentation:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html&lt;/A&gt;&amp;nbsp;it states, "&lt;/SPAN&gt;&lt;SPAN&gt;For added security and better visibility, you can create a separate zone, such as&amp;nbsp;&lt;/SPAN&gt;corp-vpn", so that's what I'm trying to do.&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;It could be just me being paranoid, but it feels wonky to have GP on my main Interface and not in a separate zone.&amp;nbsp;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;As for the loopback, I got nothing on how to make that happen.........&lt;/DIV&gt;</description>
      <pubDate>Wed, 18 Sep 2019 11:51:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288931#M76899</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-18T11:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288941#M76902</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107987"&gt;@Shawverr&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't think your grasping how the traffic flow in GlobalProtect actually works, and you completely missed where that zone statement in the configuration note comes into play &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So let's start with your zone question. The zone of your Portal and Gateway will either be your untrust zone or a DMZ zone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the tunnel interface that gets associated with the clients is what the configuration note is talking about. While you can assign the tunnel interface in your Trust zone, I 100% wouldn't recommend it. That tunnel interface should be assigned to a zone specific to VPN clients, and then security entries would be built out actually allowing traffic to/from your GlobalProtect clients.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;It might be easier to view the flow like this. The Portal provides the basic configuration and authorization of the GlobalProtect client. The client will then be passed off to the Gateway and that gateway assigns the client everything it needs to communicate and what it's allowed to communicate with. All of the traffic from the client to the gateway will be passed through the tunnel interface you created that you've assigned to a "GlobalProtect" zone, and your security policies get analyzed to see if that traffic is allowed to pass. That's an oversimplification, but it should provide you a rough flow.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 13:11:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288941#M76902</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-18T13:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288944#M76904</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thanks again, I did say coloring book and crayons.&amp;nbsp; The one thing I am sure is just how much I don't understand, LOL.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 13:30:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/288944#M76904</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-18T13:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289187#M76939</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;So I'm just going to with a really basic configuration.&amp;nbsp; I can now get the GlobalProtect Portal to come up over the Internet, but can't login.&amp;nbsp; I've been on the phone with support about this and they can't figure out why either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we don't get is why under "Session End Reason" I sometimes get (sometimes not) "decrypt-error" when I'm not set up to do decryption anywhere.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 15:18:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289187#M76939</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-19T15:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289212#M76943</link>
      <description>&lt;P&gt;What authentication method are you using for GP.&lt;/P&gt;&lt;P&gt;looking in the palo system logs may help with auth failures.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 16:54:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289212#M76943</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-19T16:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289237#M76949</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107987"&gt;@Shawverr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you trust the certificate you are using on the Portal/Gateway on the machine that you are attempting to utilize for this or not? By default, the firewall does decrypt some GlobalProtect traffic. If any auth issues are actually taking place they'll be logged in the system logs, you can filter for them with the query &lt;EM&gt;( subtype eq globalprotect )&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 20:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289237#M76949</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-19T20:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289318#M76954</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;The System log shows "'GlobalProtect portal user authentication failed. Login from: xx.xx.xx.xx, Source region: US, User name: xxxxxx, Client OS version: , Reason: Authentication failed: , Auth type: profile.'&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Chrome I do have the red "Not secure".&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 11:47:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289318#M76954</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-20T11:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289328#M76957</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;I got it!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Network&amp;lt;GlobalProtectPortals&amp;lt;portal-config&amp;gt;Authentication&amp;lt;client-authentication-config&amp;lt;OS&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We had "Windows" selected. I set that to "Any" and it works. I tried setting it to "WindowsUWP" and it still didn't work, but set to "Any" and now I can get to the download client page.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thoughts? Still a long way to go, but finally got past that part! I do appreciate all you guys help with this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 13:38:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289328#M76957</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-20T13:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289333#M76960</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Ok, next problem.&amp;nbsp; I can get connected to the Gateway and into my network with an IP from the pool range.&amp;nbsp; But I can't get to the Internet while connected to the VPN.&amp;nbsp; I think it's because the PANGP Virtual Adapter has an IP and DNS settings, but no default gateway listed.&amp;nbsp; I can't seem to figure out where to add that???&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 15:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289333#M76960</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-20T15:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289362#M76962</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107987"&gt;@Shawverr&lt;/a&gt;&amp;nbsp;, PanGP does not have or require a default gateway, default gateways are only required for last resort unknown networks, the system knows all routes are via the VPN so no gateway is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is your tunnel interface associated with a virtual router ? Also... from VPN zone to external or untrusted zone will be classed as in intrazone and not a interzone so you may require a security policy to allow interwebby stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for diagnostics add a deny all policy at the end of your policies and log session start. Then enter your PanGP address in the traffic filter to see if it’s not being allowed in other policies.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 17:21:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289362#M76962</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-20T17:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289394#M76967</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107987"&gt;@Shawverr&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Just because it catches a lot of people, ensure that you actually have security policies and a NAT policy allowing the GlobalProtect traffic outbound through&amp;nbsp; your untrust interface. Nine times out of ten, that's the issue when people can't browse when connected to GlobalProtect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 19:23:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289394#M76967</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-20T19:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289397#M76969</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;That was it guys!&amp;nbsp; Thanks again!&amp;nbsp; On to HIPS!!!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Sep 2019 19:29:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/289397#M76969</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-20T19:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290021#M77069</link>
      <description>&lt;P&gt;HIP Object &amp;gt; Custom Checks &amp;gt; Process List &amp;gt; What the heck do I got to put in there to make it work?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 16:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290021#M77069</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-25T16:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290023#M77070</link>
      <description>&lt;P&gt;I have not used the process option but i would assume it would be the name of any process you have running locally (or not) have you tried it?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 17:00:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290023#M77070</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-09-25T17:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290030#M77071</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;Hey!&amp;nbsp; Yes, I've tried C:\windows\AppName\Name.exe as well as just Name.exe - no dice.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 17:18:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290030#M77071</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-25T17:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290031#M77072</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107987"&gt;@Shawverr&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Just to verify, you do actually have a GlobalProtect subscription correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 17:19:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290031#M77072</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-09-25T17:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290032#M77073</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Yup!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2019 17:23:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290032#M77073</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-25T17:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect setup frustration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290041#M77076</link>
      <description>&lt;P&gt;I figured it out.&amp;nbsp; Just in case anyone else needs it, you have to set up a Custom Check in three places, The HIP object, the Portal and the Gateway.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Create the HIP Object&lt;OL&gt;&lt;LI&gt;Objects &amp;gt; GlobalProtect &amp;gt; HIP Objects &amp;gt; Add &amp;gt; Custom Checks &amp;gt; ProcessName.exe&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Create Portal Config&lt;OL&gt;&lt;LI&gt;Network &amp;gt; GlobalProtect &amp;gt; (click on your portal name) &amp;gt; Agent Tab &amp;gt; (open your agent config) &amp;gt; HIP Data Collection Tab &amp;gt; Custom Checks &amp;gt; Process List &amp;gt; Add &amp;gt; ProcessName.exe&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Network &amp;gt; GlobalProtect &amp;gt; (click on your Gateway name) &amp;gt; Agent Tab &amp;gt; HIP Notification Tab&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 25 Sep 2019 18:14:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-setup-frustration/m-p/290041#M77076</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-09-25T18:14:00Z</dc:date>
    </item>
  </channel>
</rss>

