GlobalProtect, enabling ipsec from outside

Reply
Highlighted
L2 Linker

GlobalProtect, enabling ipsec from outside

Hi all,

I am trying to enable Global Protect. So far I've been able to connect the client to the firewall successfully. However the remote VPN client cannot talk to inside hosts. But the inside hosts can ping the remote client.

After troubleshooting, I found  IPSec traffic is blocked at the outside interface (which blocks everything). When I enable all incoming traffic on the outside interface the remote client is able to talk to the inside zone.

I've now enabled "IPSec" application group to be passed through the outside interface, however the remote client is still unable to talk to the inside zone. Is there a standard set of applications/services that needs to be allowed on the outside interface for GlobalProtect clients?

Many thanks.

L5 Sessionator

Re: GlobalProtect, enabling ipsec from outside

On the rule that you have enabled "IPSec", please go ahead and add following as well " panos-global-protect, ike, ipsec-esp-udp, panos-web-interface, ssl". This should resolve the issue.Thanks.

L6 Presenter

Re: GlobalProtect, enabling ipsec from outside

you can allow the above said applications, alternatively you can place the tunnel interface in the internal zone that way you need not create any security policies.

L5 Sessionator

Re: GlobalProtect, enabling ipsec from outside

Did that resolved your issue? Please do let us know. Thanks.

L2 Linker

Re: GlobalProtect, enabling ipsec from outside

Putting the tunnel interface on the inside zone fixed the problem.

Opening up the apps on the outside interface did not, however I didn't have much time to troubleshoot this scenario, so it is possible I missed something.

Thanks for the help guys.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!