<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect firewall behavior after reaching max users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310631#M80443</link>
    <description>&lt;P&gt;Great explanation &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;. Thank you so much for your help.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 17:24:11 GMT</pubDate>
    <dc:creator>SuryaR</dc:creator>
    <dc:date>2020-02-11T17:24:11Z</dc:date>
    <item>
      <title>Global protect firewall behavior after reaching max users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310408#M80376</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking for more details on firewall behavior after reaching max-users limit on Global protect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, Assume a portal with 4 gateways in different regions. If one of the gateway(Lets assume PA-3020) which has capacity of 1024 concurrent connections, reached its maximum limit.&amp;nbsp; what will happen if user 1025 tries to reach 3020 during latency calculations.&lt;/P&gt;&lt;P&gt;Will GP client receive a response to TLS/SSL negotiation or will it not respond to the request.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking for details. Tried to find more details but no luck. Any help is appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 17:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310408#M80376</guid>
      <dc:creator>SuryaR</dc:creator>
      <dc:date>2020-02-10T17:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect firewall behavior after reaching max users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310417#M80377</link>
      <description>&lt;P&gt;the ssl handshake still takes place and the gateway is still given the same priority, so if the user tries to connect then the below happens and the next gateway in the priority is used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1024.jpg" style="width: 839px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23884iA8982130E4DB507F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1024.jpg" alt="1024.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 17:47:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310417#M80377</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-02-10T17:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect firewall behavior after reaching max users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310419#M80379</link>
      <description>&lt;P&gt;Great. Thank you for quick response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Couple of questions.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If user-authentication is transparently happening(lets assume certs are being used), then users will not see "authentication failed" message and move forward with associating to next gateway. ?&lt;/P&gt;&lt;P&gt;If gateways are doing second factor (token for example), then would that 1025th user, who reaches an already maxed-out gateway, see an option to enter 2fa-token (or) not.?&lt;/P&gt;&lt;P&gt;If yes, and 2FA-input is provided, will the user then see an "authentication failed" message from the maxed-out gateway and then GP-client will move on to next gateway.?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if I am not clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks Again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Surya&lt;/P&gt;</description>
      <pubDate>Mon, 10 Feb 2020 18:25:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310419#M80379</guid>
      <dc:creator>SuryaR</dc:creator>
      <dc:date>2020-02-10T18:25:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect firewall behavior after reaching max users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310521#M80400</link>
      <description>&lt;P&gt;Yes you are correct regarding certificate auth. &amp;nbsp;As user has no input.&lt;/P&gt;&lt;P&gt;this will be the same for 2fa to the portal with authentication override cookies to the gateways.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I’m not sure regarding 2fa to the gateway as we don't use it but going by the system logs i would guess that the auth will be accepted but then the gateway will fail as above it’s limit, the user would then be asked to re auth to next gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if any of our devices max out i will test this theory but it may be a while and somebody else may have the answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i cannot understand why a gateway would offer itself as available when over its limit. Perhaps that needs to be requested or perhaps they should be monitored better to prevent such an event. We use PRTG and API’s for this but setting gateway priorities is still done manually.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 05:30:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310521#M80400</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-02-11T05:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect firewall behavior after reaching max users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310631#M80443</link>
      <description>&lt;P&gt;Great explanation &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;. Thank you so much for your help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 17:24:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-firewall-behavior-after-reaching-max-users/m-p/310631#M80443</guid>
      <dc:creator>SuryaR</dc:creator>
      <dc:date>2020-02-11T17:24:11Z</dc:date>
    </item>
  </channel>
</rss>

