<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect VPN - Management Access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-vpn-management-access/m-p/297889#M78121</link>
    <description>&lt;P&gt;Thanks BatD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats something I haven't had a look at yet - I will get into the nitty gritty and see where the routing thinks this is going to be sent out. Using this in AWS currently and had to add some static routes previously so would make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Nov 2019 11:07:50 GMT</pubDate>
    <dc:creator>HyderB</dc:creator>
    <dc:date>2019-11-12T11:07:50Z</dc:date>
    <item>
      <title>GlobalProtect VPN - Management Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-vpn-management-access/m-p/297689#M78096</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know a way to get access to the panos web management interface over a globalprotect VPN? We are using three interfaces on our firewall;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 - Management Interface&lt;/P&gt;&lt;P&gt;2 - Trust&lt;/P&gt;&lt;P&gt;3 - Untrust&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Global Protect is setup on the trust - and I have a rule in the Security Policy to allow access from my device to anything - however I can't get to the interface - should this be something that should just work? I can't see any logging saying anything is denied after I have made a change?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup management access also on the trust interface for testing and I still get the same results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it not meant to be managed this way?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;BR /&gt;Stephen&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 13:53:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-vpn-management-access/m-p/297689#M78096</guid>
      <dc:creator>HyderB</dc:creator>
      <dc:date>2019-11-11T13:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect VPN - Management Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-vpn-management-access/m-p/297696#M78097</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/125918"&gt;@HyderB&lt;/a&gt;&amp;nbsp; Once a GP user has authenticated and is given IP address, then he becomes as any other network user. It is just a matter routing of security policies.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This may not be your case, but something that often goes wrong, is people not realisging that the routing of data plane interface (in your case trust and untrust) and the control plane management interface are independent of each other. Your users need to be routed correctly to you mgmt interface (if this is where you are connected to) and you mgmt interface needs to have correct routing back to the subnet of your users.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 14:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-vpn-management-access/m-p/297696#M78097</guid>
      <dc:creator>BatD</dc:creator>
      <dc:date>2019-11-11T14:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect VPN - Management Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-vpn-management-access/m-p/297889#M78121</link>
      <description>&lt;P&gt;Thanks BatD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thats something I haven't had a look at yet - I will get into the nitty gritty and see where the routing thinks this is going to be sent out. Using this in AWS currently and had to add some static routes previously so would make sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Stephen&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 11:07:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-vpn-management-access/m-p/297889#M78121</guid>
      <dc:creator>HyderB</dc:creator>
      <dc:date>2019-11-12T11:07:50Z</dc:date>
    </item>
  </channel>
</rss>

