<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Use Anyconnect to connect to Palo Alto gateway in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/use-anyconnect-to-connect-to-palo-alto-gateway/m-p/361253#M88162</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to know if its possible to configure Palo Alto GP gateway in order to permit connect using Cisco anyconnect client?&lt;/P&gt;&lt;P&gt;what it would be the config to do that?&lt;/P&gt;</description>
    <pubDate>Fri, 06 Nov 2020 10:40:25 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2020-11-06T10:40:25Z</dc:date>
    <item>
      <title>Use Anyconnect to connect to Palo Alto gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-anyconnect-to-connect-to-palo-alto-gateway/m-p/361253#M88162</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to know if its possible to configure Palo Alto GP gateway in order to permit connect using Cisco anyconnect client?&lt;/P&gt;&lt;P&gt;what it would be the config to do that?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 10:40:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-anyconnect-to-connect-to-palo-alto-gateway/m-p/361253#M88162</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-11-06T10:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Use Anyconnect to connect to Palo Alto gateway</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-anyconnect-to-connect-to-palo-alto-gateway/m-p/361307#M88169</link>
      <description>&lt;P&gt;Yes it is possible to do this.&lt;/P&gt;
&lt;P&gt;Do you have a Global Protect gateway license installed on FW?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have found this may help (not completely fix any issues)&lt;/P&gt;
&lt;P&gt;There is documentation on PANW website on how to get to the gateway config.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-gateways/configure-a-globalprotect-gateway" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-gateways/configure-a-globalprotect-gateway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Take note at task 4 ( If you Enable X-Auth Support).&amp;nbsp; You will see that it asks for a Group Name and a password, just like the Cisco AnyConnect needs a Group name and password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Now, my personal experience is this... I can get the AnyConnect to&amp;nbsp; create the tunnel to the FW, so it know it works.&lt;/P&gt;
&lt;P&gt;BUT!!!! The AnyConnect software (and NOT the PANW) puts the default gateway of the AnyConnect to the next virtual IP (from your webpool).&amp;nbsp; Example.&amp;nbsp; You config a virtual/web pool address of.. 10.99.99.0/24), so that any user (GP or AnyConnect) will get from the pool.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A GP user creates his tunnel, and gets IP 10.99.99.4/24 (just some random IP)&amp;nbsp; The GP software does NOT need/have a default gateway to route traffic across the PANW tunnel.,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Connection-specific DNS Suffix . :&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Description . . . . . . . . . . . : PANGP Virtual Ethernet Adapter&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Physical Address. . . . . . . . . : 02-50-41-00-00-01&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;DHCP Enabled. . . . . . . . . . . : No&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Autoconfiguration Enabled . . . . : Yes&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;IPv4 Address. . . . . . . . . . . : 10.99.99.4(Preferred)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Subnet Mask . . . . . . . . . . . : 255.255.255.255&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;Default Gateway . . . . . . . . . : 0.0.0.0&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;But!!!!&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The AnyConnect would get 10.99.99.5 (for example) and the default gateway would be the next IP.&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;IPv4 Address. . . . . . . . . . . : 10.99.99.5(Preferred)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Subnet Mask . . . . . . . . . . . : 255.255.255.255&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier" color="#0000FF"&gt;Default Gateway . . . . . . . . . : 10.99.99.6&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;But if 10.99.99.6 has not been assigned yet... then the tunnel (which is established correctly, according to the standards) will still not function because (for whatever reason... AnyConnect pulls 2 IPs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;So, until you contact Cisco and understand how/why their client does this... I fear that your traffic will not pass correctly.&amp;nbsp; &lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;Again, I have tested this in the past, but I am not a Cisco focused person, so who knows why this happens, but it's not a PANW issue to resolve (IMHO)&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier" color="#000000"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Nov 2020 13:49:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-anyconnect-to-connect-to-palo-alto-gateway/m-p/361307#M88169</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-11-06T13:49:20Z</dc:date>
    </item>
  </channel>
</rss>

