<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assign gateway to PanGP interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330078#M83714</link>
    <description>&lt;P&gt;No the default gateway is not configurable...&lt;/P&gt;&lt;P&gt;you probably had issues with NLA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what IP did you add to the gateway option.&amp;nbsp; was it on the same network as youre GP client receives or was it a locally connected gateway.&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2020 14:12:28 GMT</pubDate>
    <dc:creator>Mick.Ball</dc:creator>
    <dc:date>2020-05-27T14:12:28Z</dc:date>
    <item>
      <title>Assign gateway to PanGP interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330027#M83708</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have issues with a service using GP. To solve it we add the IP Palo GP tunnel in the PanGP adapter gateway in local machine. Why this is happening? is there any way to configure this pangp gateway from palo alto when user connects in GP?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 08:15:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330027#M83708</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-05-27T08:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Assign gateway to PanGP interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330078#M83714</link>
      <description>&lt;P&gt;No the default gateway is not configurable...&lt;/P&gt;&lt;P&gt;you probably had issues with NLA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what IP did you add to the gateway option.&amp;nbsp; was it on the same network as youre GP client receives or was it a locally connected gateway.&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 14:12:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330078#M83714</guid>
      <dc:creator>Mick.Ball</dc:creator>
      <dc:date>2020-05-27T14:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Assign gateway to PanGP interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330082#M83715</link>
      <description>&lt;P&gt;The IP we added for panGP gateway was the PAlo ALTO IP tunnel interface for GP&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 14:17:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330082#M83715</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-05-27T14:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: Assign gateway to PanGP interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330486#M83772</link>
      <description>&lt;P&gt;what you mean with NLA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The point is that if we add the gateway the issue are solved....weird...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 10:42:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330486#M83772</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-05-29T10:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Assign gateway to PanGP interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330575#M83795</link>
      <description>&lt;P&gt;What happens if you use the ip address of your local router...?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 17:25:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330575#M83795</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-05-29T17:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Assign gateway to PanGP interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330605#M83803</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;NLA is a Windows function. Essentially Windows by default will create a few firewall entries when you connect to any network to allow certain traffic, but since the GP tunnel doesn't have a gateway address these routes are never added. This effects primarily Microsofts Store access and UWP applications primarily from my experience, but it can technically effect other applications as well.&lt;/P&gt;&lt;P&gt;A really simple fix is to apply the following in Group Policy, which will essentially tell Microsoft to allow the traffic and you don't have to do any scripting to get the gateway assigned to the GlobalProtect interface every time a client connects.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Computer Configuration &amp;gt; Policies &amp;gt; Administrative Templates &amp;gt; Network &amp;gt; Network Isolation&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;EM&gt;Private Network ranges for apps:&amp;nbsp;&lt;/EM&gt;Enable policy and specify your GlobalProtect IP ranges under Private Subnets.&lt;/P&gt;&lt;P&gt;- &amp;nbsp;&lt;EM&gt;subnet definitions are authoritative:&amp;nbsp;&lt;/EM&gt;Enable the policy so that the above works properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With both these changes pushed out the NLA issue goes away. I would try this fix first before you attempt to actually programmatically assign the GP interface a gateway address whenever someone connects to GlobalProtect and just let those settings manage themselves as long as this takes care of your issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 18:12:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/assign-gateway-to-pangp-interface/m-p/330605#M83803</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-05-29T18:12:45Z</dc:date>
    </item>
  </channel>
</rss>

