<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GloablProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/299599#M78380</link>
    <description>&lt;P&gt;If you use a separate VR, then you'll need another interface in that new VR connected to your L3 switch for access to the networks it manages.&lt;/P&gt;&lt;P&gt;The L3 switch will also need a static route for the GP client network pointing to the new VR internal interface.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Nov 2019 23:13:14 GMT</pubDate>
    <dc:creator>rmfalconer</dc:creator>
    <dc:date>2019-11-19T23:13:14Z</dc:date>
    <item>
      <title>GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/297834#M78113</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am new to palo alto. we have deployed some firewalls in our company. I am trying to configure globlalprotect on the branch offices to add more gateways. I have an extra internet connection at one location and wanted to know if its possible to configure global protect on one of the interfaces.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the firewall is currently behind a cisco router an connect to our switch. ut i wanted to configure on interface with the the extra internet provider and configure GP. I configured the interface with the public IP and a PBF rule since I already have a default route configured. But is not responding to ping to that interface. is this possible ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Globalprotect.PNG" style="width: 726px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22234i22C9262EDEFE4529/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Globalprotect.PNG" alt="Globalprotect.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 01:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/297834#M78113</guid>
      <dc:creator>Ralvarado10</dc:creator>
      <dc:date>2019-11-12T01:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/297841#M78116</link>
      <description>&lt;P&gt;Yes, it is possible to do what you are attempting to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are not getting pings to work, then you would need to look at your logs to see IF you FW sees the pings coming inbound from the extra ISP network (or similar).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You would also want to confirm that you have a interface mgmt profile enabled on the 2nd FW public interface, that allows ping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other questions can we answer for you?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 07:11:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/297841#M78116</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-12T07:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/297986#M78133</link>
      <description>&lt;P&gt;Another option would be to create a separate virtual router for the other ISP connection and keep the GP traffic on that. That way you can manage routing separately and not worry about PBF.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 17:02:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/297986#M78133</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-11-12T17:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/298141#M78152</link>
      <description>&lt;P&gt;Hello Steve,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes I have the ping profile configured for that ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you see that 1/1 connecting to the router is not a public ip. I am sending the default router with static routes and NAT is not configured since the router is doing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clipboard_image_0.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22306i9F561E45BB86D22F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="clipboard_image_0.png" alt="clipboard_image_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 00:01:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/298141#M78152</guid>
      <dc:creator>Ralvarado10</dc:creator>
      <dc:date>2019-11-13T00:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/298169#M78157</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100267"&gt;@Ralvarado10&lt;/a&gt;&amp;nbsp; you have me a little confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see that ethernet1/1 is your primary ISP, with a private IP.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have connected your DSL to your ethernet 1/5, with a public IP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You stated you could not ping the portal (at least that was my understanding), and you responded that you had the ping enabled on ethernet1/1... but your portal is on ethernet1/5.&amp;nbsp; &amp;nbsp;I do see that your portal has a ping-only profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do your traffic logs show, when you try to ping the portal's IP from the DSL ISP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 05:32:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/298169#M78157</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-11-13T05:32:02Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/299597#M78379</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ended up creating a&amp;nbsp; VR for this ISP and now I am able to connect now. i configured GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the only issue that I am having now is that I cannot access the internal network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any ideas ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your help is appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 22:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/299597#M78379</guid>
      <dc:creator>Ralvarado10</dc:creator>
      <dc:date>2019-11-19T22:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/299599#M78380</link>
      <description>&lt;P&gt;If you use a separate VR, then you'll need another interface in that new VR connected to your L3 switch for access to the networks it manages.&lt;/P&gt;&lt;P&gt;The L3 switch will also need a static route for the GP client network pointing to the new VR internal interface.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 23:13:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/299599#M78380</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2019-11-19T23:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/299656#M78388</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100267"&gt;@Ralvarado10&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/55733"&gt;@rmfalconer&lt;/a&gt;&amp;nbsp;mentioned is one way of doing things, however not what I would do in your case as you are wasting ports. When you configure a route you will use the option "Next VR" under your next hop setting and you can pass the traffic to your primary VR without needing to dedicate a port simply to route the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 02:56:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/299656#M78388</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-11-20T02:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: GloablProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/300672#M78553</link>
      <description>&lt;P&gt;Thank you all for all the help I got from you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a separate VR for the second ISP as recommended. I also try both solution to configure another interface&amp;nbsp; and connect it to the core, as well as the one where you point the static route to the other "VR". both worked but as mention by&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_self"&gt;BPry&lt;/A&gt;&amp;nbsp;to reduce the ports I used the option of the Next VR and worked perfect .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;thank you all again for helping me with this.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 22:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gloablprotect/m-p/300672#M78553</guid>
      <dc:creator>Ralvarado10</dc:creator>
      <dc:date>2019-11-25T22:06:48Z</dc:date>
    </item>
  </channel>
</rss>

