<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to reach GP Portal while on internal network in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/318014#M81707</link>
    <description>&lt;P&gt;I was able to resolve this by excluding the GP portal from the PBF rule and then create a static route on the VR&lt;/P&gt;</description>
    <pubDate>Mon, 23 Mar 2020 17:16:25 GMT</pubDate>
    <dc:creator>ce1028</dc:creator>
    <dc:date>2020-03-23T17:16:25Z</dc:date>
    <item>
      <title>Unable to reach GP Portal while on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/314835#M81171</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was working with a site that has a PA firewall with a GP Portal and Gateway.&amp;nbsp; Some time ago, I had an issue where my users couldn't upgrade their globalprotect version while in the office. I was able to resolve this issue by creating a No NAT rule where if the source was internal and the destination was the IP of the portal.&amp;nbsp; That works as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm now working with another site that has a GP Portal/Gateway on the firewall, I created the same No Nat rule, but these users are still not able to upgrade internally, they are not prompted.&amp;nbsp; They are not even able to hit the web portal.&amp;nbsp; The difference in this site is they are using a dual ISP setup.&amp;nbsp; This is setup using PBF.&amp;nbsp; e1/1 is the primary ISP, so there is the typical PBF rule for external traffic to forward out e1/1. &amp;nbsp; I'm not sure if the issue is related to PBF.&amp;nbsp; Has anyone come across this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 01:25:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/314835#M81171</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2020-03-06T01:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to reach GP Portal while on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/314872#M81177</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please make sure, that the users have a exception in the pbf rule, so they will led to the public interface with the gp portal.&lt;/P&gt;&lt;P&gt;Otherwise they will be forced to the wrong public interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chacko&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 09:28:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/314872#M81177</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2020-03-06T09:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to reach GP Portal while on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/314962#M81183</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure I'm clear what you mean?&amp;nbsp; The GP Portal is the IP of the e1/1 interface.&amp;nbsp; The PBF rule states if you from source internal to external, forward to e1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried creating a no PBF rule for the specific GP IP, but then that made things worse&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 18:23:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/314962#M81183</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2020-03-06T18:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to reach GP Portal while on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/315010#M81188</link>
      <description>&lt;P&gt;Is there a security policy allowing ssl and panos-global-protect from your inside zone to the zone/address of the portal?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 21:39:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/315010#M81188</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-06T21:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to reach GP Portal while on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/318014#M81707</link>
      <description>&lt;P&gt;I was able to resolve this by excluding the GP portal from the PBF rule and then create a static route on the VR&lt;/P&gt;</description>
      <pubDate>Mon, 23 Mar 2020 17:16:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-reach-gp-portal-while-on-internal-network/m-p/318014#M81707</guid>
      <dc:creator>ce1028</dc:creator>
      <dc:date>2020-03-23T17:16:25Z</dc:date>
    </item>
  </channel>
</rss>

