<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Untrust interface we have created Global protect gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339459#M85239</link>
    <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sonu_Singh_0-1595145568421.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26919iBB38B2BB68AD37F8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sonu_Singh_0-1595145568421.png" alt="Sonu_Singh_0-1595145568421.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;we have separated GP portal and GP gateway interface.&lt;/P&gt;&lt;P&gt;Untrust interface we have created Global protect gateway and we allowed ping on the interface but when we are typing untrust interface IP address on our browser eg &lt;A href="https://112.20.20.1" target="_blank"&gt;https://112.20.20.1&lt;/A&gt;&amp;nbsp;. We are getting the above message 502 bad gateway.&lt;/P&gt;&lt;P&gt;Qustion :we have only allowed ping on GP gateway interface ...why https or https port open here ??&lt;/P&gt;&lt;P&gt;Is that normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 19 Jul 2020 08:11:46 GMT</pubDate>
    <dc:creator>bit_byte</dc:creator>
    <dc:date>2020-07-19T08:11:46Z</dc:date>
    <item>
      <title>Untrust interface we have created Global protect gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339459#M85239</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sonu_Singh_0-1595145568421.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26919iBB38B2BB68AD37F8/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sonu_Singh_0-1595145568421.png" alt="Sonu_Singh_0-1595145568421.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;we have separated GP portal and GP gateway interface.&lt;/P&gt;&lt;P&gt;Untrust interface we have created Global protect gateway and we allowed ping on the interface but when we are typing untrust interface IP address on our browser eg &lt;A href="https://112.20.20.1" target="_blank"&gt;https://112.20.20.1&lt;/A&gt;&amp;nbsp;. We are getting the above message 502 bad gateway.&lt;/P&gt;&lt;P&gt;Qustion :we have only allowed ping on GP gateway interface ...why https or https port open here ??&lt;/P&gt;&lt;P&gt;Is that normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 08:11:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339459#M85239</guid>
      <dc:creator>bit_byte</dc:creator>
      <dc:date>2020-07-19T08:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: Untrust interface we have created Global protect gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339518#M85251</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you check the monitor tab of you see this connection in your logs?&lt;/P&gt;
&lt;P&gt;In addition, what PAN-OS version do you have installed?&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 22:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339518#M85251</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-07-19T22:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Untrust interface we have created Global protect gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339527#M85254</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the GP Gateway Interface and your Interface connected to ISP belongs to same untrust zone thats the reason you are able to access the GP on port 443.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is Intrazone traffic which is allowed by default.&lt;/P&gt;
&lt;P&gt;Please check your Traffic logs as next step as mentioned by the Remo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 02:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339527#M85254</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2020-07-20T02:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Untrust interface we have created Global protect gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339540#M85258</link>
      <description>&lt;P&gt;GP gateway&amp;nbsp; zone:VPN_zone&lt;BR /&gt;outside inteface:Untrust_zone&lt;/P&gt;&lt;P&gt;Both are different zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes traffic is hitting intrazone&amp;nbsp;&lt;/P&gt;&lt;P&gt;249916 ssl DISCARD FLOW *ND 84.210.70.110[54375]/Untrust/6 (84.210.70.110&lt;BR /&gt;92[54375])&lt;BR /&gt;vsys1 112.20.20.1 [443]/Untrust (112.20.20.1 [2&lt;BR /&gt;0077])&lt;BR /&gt;124853 ssl DISCARD FLOW *ND 84.210.70.110[54379]/Untrust/6 (84.210.70.110&lt;BR /&gt;92[54379])&lt;BR /&gt;vsys1 112.20.20.1 [443]/Untrust (112.20.20.1 [2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;OS version:9.0.8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="monitor_traffic.PNG" style="width: 954px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/26922i5F19822A4E4DB748/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="monitor_traffic.PNG" alt="monitor_traffic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;untrust interface we have applied management profile and we have only allowed ping but why it is listening to HTTP or https traffic.&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 05:47:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339540#M85258</guid>
      <dc:creator>bit_byte</dc:creator>
      <dc:date>2020-07-20T05:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Untrust interface we have created Global protect gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339542#M85260</link>
      <description>&lt;P&gt;thats why I don't like these defaul firewallrules ... I always overwrite them with a dedicated deny all rules which I configure above these default rules.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132490"&gt;@bit_byte&lt;/a&gt; Global Protect portal/gateway access cannot be enabled/allowed by a management profile. As the name implies, this management profile mainly is for management services. So if you enable https in a management profile you would enable the firewall management interface and not something related to global protect. Globalprotect access you need to configure in the security policy.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2020 06:34:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/untrust-interface-we-have-created-global-protect-gateway/m-p/339542#M85260</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2020-07-20T06:34:04Z</dc:date>
    </item>
  </channel>
</rss>

