<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple URL Global Protect Multiple FQDN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303260#M78950</link>
    <description>&lt;P&gt;Even though we own each company we want them to have that feel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each company has its own AD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could possibly set an authentication order but than they have to login with like &lt;A href="mailto:username@ADdomain.local" target="_blank"&gt;username@ADdomain.local&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also many times we have the same username at both companys.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2019 17:06:25 GMT</pubDate>
    <dc:creator>ChrisGapske</dc:creator>
    <dc:date>2019-12-11T17:06:25Z</dc:date>
    <item>
      <title>Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303247#M78944</link>
      <description>&lt;P&gt;We would like to use multiple URL's to access our Palo with Multiple LDAP authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;portal.company1.com&amp;nbsp;&lt;/P&gt;&lt;P&gt;LDAP1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;portal.company2.com&lt;/P&gt;&lt;P&gt;LDAP2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;portal.company3.com&lt;/P&gt;&lt;P&gt;LDAP3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We could also do like&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C1.company.com&lt;/P&gt;&lt;P&gt;LDAP1&lt;/P&gt;&lt;P&gt;C2company.com&lt;/P&gt;&lt;P&gt;LDAP2&lt;/P&gt;&lt;P&gt;C3company.com&lt;/P&gt;&lt;P&gt;LDAP3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anybody guide me to a solution so far support has not been super helpfull.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another is portal.company&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with authentication sequence but that requires more work for the users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am a little new to Palo could use help .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 16:31:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303247#M78944</guid>
      <dc:creator>ChrisGapske</dc:creator>
      <dc:date>2019-12-11T16:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303255#M78945</link>
      <description>&lt;P&gt;I'm looking to do something similar. I have 2 Palo's both with a GP gateways setup and I'm thinking of using DNS roundrobin to hit either one of them using a single Portal URL company.domain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if this is the best way to do it or not. But basically i want clients to only have to configure 1 Portal URL on the client and then hit either one of my palo's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 16:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303255#M78945</guid>
      <dc:creator>athalman</dc:creator>
      <dc:date>2019-12-11T16:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303256#M78946</link>
      <description>&lt;P&gt;You really want to do multiple gateways then ?&amp;nbsp; This is sorta the other way around.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 16:51:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303256#M78946</guid>
      <dc:creator>ChrisGapske</dc:creator>
      <dc:date>2019-12-11T16:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303257#M78947</link>
      <description>&lt;P&gt;Yes since I have 2 egress points in my network, each one with a Palo. In case of fail over or an outage at one location, i want my users to hit the other Palo and still have access to the network. I was hoping to achieve this by using a DNS entry with 2 ips pointing to each one of my Gateways. which would have the same name of course.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's mainly going to be used during maintenance windows/outages really. Either Palo can handle all my VPN connections individually but i'm trying to give the highest VPN availability i can.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 16:57:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303257#M78947</guid>
      <dc:creator>athalman</dc:creator>
      <dc:date>2019-12-11T16:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303258#M78948</link>
      <description>&lt;P&gt;You can do that too. When you use the gateway it allows for that as well as mulitple ip addresses and the client will do the work from there but ... The timeout might be a factor IDk&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 17:01:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303258#M78948</guid>
      <dc:creator>ChrisGapske</dc:creator>
      <dc:date>2019-12-11T17:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303259#M78949</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128524"&gt;@ChrisGapske&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you explain why you need seperate ldap auths for each company.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you not just set an authentication order for all your ldap profiles and the user will auth to the correct one.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/99548"&gt;@athalman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this will work as a good RR solution but load balancing will not be guaranteed, do you not have a "Gateway" license.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 17:01:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303259#M78949</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-12-11T17:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303260#M78950</link>
      <description>&lt;P&gt;Even though we own each company we want them to have that feel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Each company has its own AD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could possibly set an authentication order but than they have to login with like &lt;A href="mailto:username@ADdomain.local" target="_blank"&gt;username@ADdomain.local&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also many times we have the same username at both companys.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 17:06:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303260#M78950</guid>
      <dc:creator>ChrisGapske</dc:creator>
      <dc:date>2019-12-11T17:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303261#M78951</link>
      <description>&lt;P&gt;thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;I'm going to test it this Friday evening. I'll let you all know if it works out or not!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 17:07:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303261#M78951</guid>
      <dc:creator>athalman</dc:creator>
      <dc:date>2019-12-11T17:07:25Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303264#M78952</link>
      <description>&lt;P&gt;sorry i meant auth sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so just add a new portal for each company, this will require an IP address for each one though.&lt;/P&gt;&lt;P&gt;then add LDAP profile to each portal. each portal will then have its own gateway on same ip address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can still use auth sequence on a single portal as it will try every ldap server until succesful.&lt;/P&gt;&lt;P&gt;also... ldap failed auth will not loch an account. you do not need to add domain info for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 17:24:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303264#M78952</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-12-11T17:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303848#M79057</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually he (&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128524"&gt;@ChrisGapske&lt;/a&gt;) need to have users typing domain along their username.&lt;/P&gt;&lt;P&gt;As you pointed out Authentication Sequence will try to authenticate a user from top to bottom. This could be a problem if you have exact same usernames in multiple domains.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Starting from 8.1 (or even 8.0 not sure exactly) authentication sequence have option to use the typed domain to determine which profile to use from the list and jump straight to it, instead of going top to bottom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Use domain to determine authentication profile
	
Select this option (selected by default) if you want the firewall to match the domain name that a user enters during login with the User Domain
or Kerberos Realm
of an authentication profile associated with the sequence and then use that profile to authenticate the user. The user input that the firewall uses for matching can be the text preceding the username (with a backslash separator) or the text following the username (with a @ separator). If the firewall does not find a match, it tries the authentication profiles in the sequence in top-to-bottom order.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/device/device-authentication-sequence.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/device/device-authentication-sequence.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 11:28:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303848#M79057</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-12-16T11:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple URL Global Protect Multiple FQDN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303850#M79059</link>
      <description>&lt;P&gt;yes of course but i think&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/128524"&gt;@ChrisGapske&lt;/a&gt;&amp;nbsp;was hoping not to have the users adding the domain to the username.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps if users exist on both domains the would have different passwords so authentication sequence would work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if the passwords for both users were the same then why would that matter...&amp;nbsp; &amp;nbsp;they would still logon.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Dec 2019 11:39:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-url-global-protect-multiple-fqdn/m-p/303850#M79059</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-12-16T11:39:34Z</dc:date>
    </item>
  </channel>
</rss>

