<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect pre-logon and user IP Pools in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414764#M93173</link>
    <description>&lt;P&gt;I can show via 2 screen shots&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here, i just cloned my gateway config, to simulate wanting to have the same subnet used by 2 profiles&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_1-1624460012393.png" style="width: 887px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34547iFFC013E2BC6B6C56/image-dimensions/887x51?v=v2" width="887" height="51" role="button" title="SteveCantwell_1-1624460012393.png" alt="SteveCantwell_1-1624460012393.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I commit, the validation fails and you cannot commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1624460002989.png" style="width: 580px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34546i5E29B9B08F9F0FCD/image-dimensions/580x119?v=v2" width="580" height="119" role="button" title="SteveCantwell_0-1624460002989.png" alt="SteveCantwell_0-1624460002989.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As I mentioned, I have experienced this first hand.&amp;nbsp; My recommendation is that you define (2) /25 subnets, one for prelogin and one for your remaining users.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jun 2021 14:58:03 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2021-06-23T14:58:03Z</dc:date>
    <item>
      <title>Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414429#M93123</link>
      <description>&lt;P&gt;I'm wondering if anyone can help. We have global protect setup and i want to use the same IP Pool for pre-logon user's, and once authenticated have that same IP pool used for the user. So when i am setting this up in the client settings area of the Global Protect gateway area, i would like to add a pre-logon profile with a pool, then add the users profile with the same IP Pool. Attached is a screen shot of the configuration area&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 08:44:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414429#M93123</guid>
      <dc:creator>markdaniel</dc:creator>
      <dc:date>2021-06-22T08:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414434#M93125</link>
      <description>&lt;P&gt;...&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 15:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414434#M93125</guid>
      <dc:creator>markdaniel</dc:creator>
      <dc:date>2021-06-23T15:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414546#M93143</link>
      <description>&lt;P&gt;Hello there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried this before, and the OS will not allow it.&amp;nbsp; What I typically do, is take a /24 and break it into a /25.&lt;/P&gt;
&lt;P&gt;This way half of your prelogin will get a subnet that is still routable, so when they actually log onto the computer (user login) they are getting a different IP from the 2nd subnet... but from a routing table perspective, you can just add a /24 to your routing table to route the traffic to your FW (default gateway)&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 17:23:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414546#M93143</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-22T17:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414577#M93149</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153146"&gt;@markdaniel&lt;/a&gt;&amp;nbsp;, sorry to ask as may have misread post but if you require the same pool then why create a separate profile for pre logon users...?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 19:25:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414577#M93149</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-06-22T19:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414661#M93158</link>
      <description>&lt;P&gt;We have multiple user profiles in the client settings for different customers, not all of them use pre-logon. We have one set of customers that use pre-logon so we have a pre-logon profile and an users profile in the client settings. They both have different IP pools. My question is, can we somehow have the ip pools the same for the 2 client profiles or not?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 07:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414661#M93158</guid>
      <dc:creator>markdaniel</dc:creator>
      <dc:date>2021-06-23T07:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414725#M93167</link>
      <description>&lt;P&gt;The answer is no.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 13:19:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414725#M93167</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-23T13:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414759#M93172</link>
      <description>&lt;P&gt;OK thanks, I'm happy to accept, can you point me at any documentation to say that isn't supported? or is it supported in version 10?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 14:47:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414759#M93172</guid>
      <dc:creator>markdaniel</dc:creator>
      <dc:date>2021-06-23T14:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414764#M93173</link>
      <description>&lt;P&gt;I can show via 2 screen shots&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here, i just cloned my gateway config, to simulate wanting to have the same subnet used by 2 profiles&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_1-1624460012393.png" style="width: 887px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34547iFFC013E2BC6B6C56/image-dimensions/887x51?v=v2" width="887" height="51" role="button" title="SteveCantwell_1-1624460012393.png" alt="SteveCantwell_1-1624460012393.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When I commit, the validation fails and you cannot commit.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SteveCantwell_0-1624460002989.png" style="width: 580px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/34546i5E29B9B08F9F0FCD/image-dimensions/580x119?v=v2" width="580" height="119" role="button" title="SteveCantwell_0-1624460002989.png" alt="SteveCantwell_0-1624460002989.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As I mentioned, I have experienced this first hand.&amp;nbsp; My recommendation is that you define (2) /25 subnets, one for prelogin and one for your remaining users.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 14:58:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414764#M93173</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2021-06-23T14:58:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414765#M93174</link>
      <description>&lt;P&gt;Oh I see....&amp;nbsp; &amp;nbsp;but what would happen if you did not put IP pools in each of the gateway\client\configs and put one big pool in the gateway\agent\client ip pool?&amp;nbsp; would each user get their own profile (for whatever reason) and all share the same pool...?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 15:03:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414765#M93174</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-06-23T15:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414888#M93196</link>
      <description>&lt;P&gt;With the proposal of &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;it definately is possible to have the same IP pool for different client settings. But as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153146"&gt;@markdaniel&lt;/a&gt;&amp;nbsp;wrote there are also different customers on that same gateway so I don't know if it is ok if all these users from different customers are in the same IP pool. Another possibility would be to add multiple global protect gateways - one for each customer or one for clients without pre logon and one for prelogon users. This way everythings can be separated even better. Portal could still be the same for the diffetent customers.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 23:08:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414888#M93196</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-23T23:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414973#M93204</link>
      <description>&lt;P&gt;Thanks for your response but we only have the 1 VM-Series Firewall.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 11:06:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/414973#M93204</guid>
      <dc:creator>markdaniel</dc:creator>
      <dc:date>2021-06-24T11:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect pre-logon and user IP Pools</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/415039#M93211</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153146"&gt;@markdaniel&lt;/a&gt;&amp;nbsp;Even on one firewall you can have more than one global protect gateway configuration.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 15:11:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-pre-logon-and-user-ip-pools/m-p/415039#M93211</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2021-06-24T15:11:23Z</dc:date>
    </item>
  </channel>
</rss>

