<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What can I do with a Global proect subscription? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/339127#M85205</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2280"&gt;@darren_g&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Honestly before you do anything else, I would recommend setting up HIP checks to ensure endpoint compliance and securing any critical workloads with HIP match requirements. So something like file server access should require that the endpoint is actually up-to-date and that it has some form of antivirus installed.&lt;/P&gt;&lt;P&gt;This is more important now that we have so much WFH across most of the world and a record number of BYOD endpoints being used on enterprise networks. You want to make sure that those endpoints don't bring something into your network, and HIP checks allow you to do that if configured correctly.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've already got that on my radar, definitely. That's one of the major reasons (along with client-less VPN) I purchased the subscription when I got the new firewalls.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2020 02:18:59 GMT</pubDate>
    <dc:creator>darren_g</dc:creator>
    <dc:date>2020-07-17T02:18:59Z</dc:date>
    <item>
      <title>What can I do with a Global proect subscription?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336552#M84771</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;(posted this in the global protect forum, but this seems to get more traffic, and maybe more suggestions, so I moved it here)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I'm about due to retire my old 3050's and upgrade to 3250's - and this time I've convinced management to buy me the global protect subscription by pointing out that the changes in the way it operates after software version 8.1 remove the ability to split-tunnel for remotes, and would add load to the edge - so I win. Previously, I've just run with no license, and run the portal/gateway on the one box without any of the bells and whistles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But what can I do with the subscription license? Things I want to consider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Run two gateways - one for company PC's with pre-login enabled, and one for non-company PC's which just uses the old fashioned way of logging in. Can I do this on the same physical hardware by creating two portals (I have multiple external IP's I can bind to the outside interface of the firewall), or won't that work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Create some kind of jump page or remote access page for users to login to selected apps/services without using the VPN client. Is that what Palo Alto call "clientless VPN"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What other nifty stuff can I do with this new found power? Can someone point me to decent how-to's for making this kind of stuff work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 03 Jul 2020 02:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336552#M84771</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2020-07-03T02:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: What can I do with a Global proect subscription?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336569#M84777</link>
      <description>&lt;P&gt;Here is feature list&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Generally licenses are needed:&lt;/P&gt;&lt;P&gt;- mobile devices&lt;/P&gt;&lt;P&gt;- higher security - HIPS check&lt;/P&gt;&lt;P&gt;- clientless&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. No, ip should be binded to interface. U can acheive it by configuring portal with loopback and NAT&lt;/P&gt;&lt;P&gt;2. Yes, exactly&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 10:03:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336569#M84777</guid>
      <dc:creator>pawelzwierz</dc:creator>
      <dc:date>2020-07-03T10:03:27Z</dc:date>
    </item>
    <item>
      <title>Re: What can I do with a Global proect subscription?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336599#M84797</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2280"&gt;@darren_g&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Honestly before you do anything else, I would recommend setting up HIP checks to ensure endpoint compliance and securing any critical workloads with HIP match requirements. So something like file server access should require that the endpoint is actually up-to-date and that it has some form of antivirus installed.&lt;/P&gt;
&lt;P&gt;This is more important now that we have so much WFH across most of the world and a record number of BYOD endpoints being used on enterprise networks. You want to make sure that those endpoints don't bring something into your network, and HIP checks allow you to do that if configured correctly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 13:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336599#M84797</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-07-04T13:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: What can I do with a Global proect subscription?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336686#M84847</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52833"&gt;@pawelzwierz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Here is feature list&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Generally licenses are needed:&lt;/P&gt;
&lt;P&gt;- mobile devices&lt;/P&gt;
&lt;P&gt;- higher security - HIPS check&lt;/P&gt;
&lt;P&gt;- clientless&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. No, ip should be binded to interface. U can acheive it by configuring portal with loopback and NAT&lt;/P&gt;
&lt;P&gt;2. Yes, exactly&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;To add to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52833"&gt;@pawelzwierz&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; mentioned.&amp;nbsp; Palo in the "unlicensed" version of GP provides a robust client based VPN.&amp;nbsp; There's really not anything lacking in this posture.&amp;nbsp; In the unlicensed version there's no restrictions on capacity or throughput HIP even works for alerting and awareness.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HIP &lt;STRONG&gt;enforcement&lt;/STRONG&gt; however comes in the licensed version.&amp;nbsp; The clientless VPN portal also needs a license which is something you said you're looking for.&amp;nbsp; I think these two features alone should be able to help you justify the license purchase.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 15:54:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/336686#M84847</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2020-07-06T15:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: What can I do with a Global proect subscription?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/339127#M85205</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/2280"&gt;@darren_g&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Honestly before you do anything else, I would recommend setting up HIP checks to ensure endpoint compliance and securing any critical workloads with HIP match requirements. So something like file server access should require that the endpoint is actually up-to-date and that it has some form of antivirus installed.&lt;/P&gt;&lt;P&gt;This is more important now that we have so much WFH across most of the world and a record number of BYOD endpoints being used on enterprise networks. You want to make sure that those endpoints don't bring something into your network, and HIP checks allow you to do that if configured correctly.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've already got that on my radar, definitely. That's one of the major reasons (along with client-less VPN) I purchased the subscription when I got the new firewalls.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 02:18:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/339127#M85205</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2020-07-17T02:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: What can I do with a Global proect subscription?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/339130#M85206</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52833"&gt;@pawelzwierz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Here is feature list&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Generally licenses are needed:&lt;/P&gt;&lt;P&gt;- mobile devices&lt;/P&gt;&lt;P&gt;- higher security - HIPS check&lt;/P&gt;&lt;P&gt;- clientless&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. No, ip should be binded to interface. U can acheive it by configuring portal with loopback and NAT&lt;/P&gt;&lt;P&gt;2. Yes, exactly&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;In regard to point 1 - what if I bind a second IP address to the interface - can I run one portal on one IP address, and another on he second?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 02:20:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/339130#M85206</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2020-07-17T02:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: What can I do with a Global proect subscription?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/339132#M85207</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52833"&gt;@pawelzwierz&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Here is feature list&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Generally licenses are needed:&lt;/P&gt;&lt;P&gt;- mobile devices&lt;/P&gt;&lt;P&gt;- higher security - HIPS check&lt;/P&gt;&lt;P&gt;- clientless&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. No, ip should be binded to interface. U can acheive it by configuring portal with loopback and NAT&lt;/P&gt;&lt;P&gt;2. Yes, exactly&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;To add to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52833"&gt;@pawelzwierz&lt;/a&gt;&amp;nbsp; and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; mentioned.&amp;nbsp; Palo in the "unlicensed" version of GP provides a robust client based VPN.&amp;nbsp; There's really not anything lacking in this posture.&amp;nbsp; In the unlicensed version there's no restrictions on capacity or throughput HIP even works for alerting and awareness.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HIP &lt;STRONG&gt;enforcement&lt;/STRONG&gt; however comes in the licensed version.&amp;nbsp; The clientless VPN portal also needs a license which is something you said you're looking for.&amp;nbsp; I think these two features alone should be able to help you justify the license purchase.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;There is, actually, in unlicensed - once you install software above the 8.0 series on the firewall, you lose the ability to split-tunnel in the unlicensed version of global protect - something which is critical to my installation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've already got the license - I don't need to justify it - I just want to get the most out of it when I get the firewalls actually installed. HIP enforcement is the first thing on my list, for sure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your input&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 02:24:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/what-can-i-do-with-a-global-proect-subscription/m-p/339132#M85207</guid>
      <dc:creator>darren_g</dc:creator>
      <dc:date>2020-07-17T02:24:44Z</dc:date>
    </item>
  </channel>
</rss>

