<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect (basic-mode) for Android and PC - licensing and coexistence in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-basic-mode-for-android-and-pc-licensing-and/m-p/1066#M826</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Don,&lt;/P&gt;&lt;P&gt;We came across a similar requirement as we operate in a mixed device environment and as such use android/ios devices with Xauth-psk (using the native OS client) as opposed to certificates and accept the tradeoff between risk/functionality. &lt;/P&gt;&lt;P&gt;Just in case it gives you ideas on how to solve your second interface issue, we use the single portal instance configured with multiple gateways (bound to loopbacks) such that a windows/mac device wishing to run the globalprotect client can point at the portal and receive its configuration, whilst other devices can point at the address of their gateway to establish the IPSec tunnel and obtain appropriate IP addressing/policies etc. &lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;damian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Nov 2012 20:08:45 GMT</pubDate>
    <dc:creator>dsouthard</dc:creator>
    <dc:date>2012-11-12T20:08:45Z</dc:date>
    <item>
      <title>Global Protect (basic-mode) for Android and PC - licensing and coexistence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-basic-mode-for-android-and-pc-licensing-and/m-p/1064#M824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone, one of my customers wants to connect using their Android smartphone.&amp;nbsp; I read the doc, seems like the only gotcha is it requires client certs.&amp;nbsp; If I do this, then all SSLVPN users will be required to have client certs.&amp;nbsp; I did not see a way to allow android/ios devices to use client certs while allowing PC's to simply connect in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else been faced by this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also - there is the question of licensing.&amp;nbsp; I have received different answers so I am asking once again,.&amp;nbsp; If I understand correctly:&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; The PA comes with a portal and SINGLE gw (no license required)&amp;nbsp; &lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&amp;nbsp; I wanted to have a 2nd sslvpn on a second WAN interface, then I would need to purchase a "gateway License."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is in a HA pair- so will I need a 2nd license\for the Passive PA firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any verification of this woudl be much appreciated,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Don &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Nov 2012 20:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-basic-mode-for-android-and-pc-licensing-and/m-p/1064#M824</guid>
      <dc:creator>dbrenipc</dc:creator>
      <dc:date>2012-11-08T20:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect (basic-mode) for Android and PC - licensing and coexistence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-basic-mode-for-android-and-pc-licensing-and/m-p/1065#M825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;License requirements ::&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GlobalProtect portal license is one time permanent license. The gateway license is a one or three year&lt;/P&gt;&lt;P&gt;subscription license.&lt;/P&gt;&lt;P&gt;1. No license is required for single portal/ gateway deployment without Host checks&lt;/P&gt;&lt;P&gt;2. Only&amp;nbsp; a portal license is required for multiple gateway deployment without Host check&lt;/P&gt;&lt;P&gt;3. Portal license and gateway subscription license is required when Host check is implemented, either&lt;/P&gt;&lt;P&gt;with single or multiple gateways&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;2nd sslvpn on a second WAN interface would be a Multiple Gateway with Single Portal&amp;nbsp; which would need a&amp;nbsp; portal license.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;This is in a HA pair- so will I need a 2nd license\for the Passive PA firewall? :&lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12px; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Ref:&lt;SPAN style="font-size: 11.0pt; font-family: 'Calibri','sans-serif';"&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2020"&gt;https://live.paloaltonetworks.com/docs/DOC-2020&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Nov 2012 07:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-basic-mode-for-android-and-pc-licensing-and/m-p/1065#M825</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-11-09T07:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect (basic-mode) for Android and PC - licensing and coexistence</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-basic-mode-for-android-and-pc-licensing-and/m-p/1066#M826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Don,&lt;/P&gt;&lt;P&gt;We came across a similar requirement as we operate in a mixed device environment and as such use android/ios devices with Xauth-psk (using the native OS client) as opposed to certificates and accept the tradeoff between risk/functionality. &lt;/P&gt;&lt;P&gt;Just in case it gives you ideas on how to solve your second interface issue, we use the single portal instance configured with multiple gateways (bound to loopbacks) such that a windows/mac device wishing to run the globalprotect client can point at the portal and receive its configuration, whilst other devices can point at the address of their gateway to establish the IPSec tunnel and obtain appropriate IP addressing/policies etc. &lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;damian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Nov 2012 20:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-basic-mode-for-android-and-pc-licensing-and/m-p/1066#M826</guid>
      <dc:creator>dsouthard</dc:creator>
      <dc:date>2012-11-12T20:08:45Z</dc:date>
    </item>
  </channel>
</rss>

