Query on GlobalProtect SSL VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Query on GlobalProtect SSL VPN

L4 Transporter

Hello,

 

I’ve got a single public IP address, which is used for GlobalProtect SSL VPN. I also want use this single public IP address to allow inbound static NAT to a SSL web server on my LAN. 

 

Using GP 4.0.5

 

When I do this, the GlobalProtect SSL VPN client stops working and starts redirecting the traffic to the SSL web server. Is there a way around this so that both the GlobalProtect SSL VPN client and SSL web server will work on a single public IP address without having to use a separate IP address?

 

Thanks in advance!

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

hi @Farzana

 

there's no "clean" way to accomplish this since you're trying to share the same port between 2 services

 

one workaround is to enable the gateway on a loopback interface, then set up NAT to redirect a 'different' external port (eg. 5000) to 443 onto the loopback. that way your GP client will connect to the gateway via port 5000 which the firewall will NAT to 443 on the loopback

 

portal may only be accessible from LAN as you can't use the same trick for portal

 

port 5000.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

hi @Farzana

 

there's no "clean" way to accomplish this since you're trying to share the same port between 2 services

 

one workaround is to enable the gateway on a loopback interface, then set up NAT to redirect a 'different' external port (eg. 5000) to 443 onto the loopback. that way your GP client will connect to the gateway via port 5000 which the firewall will NAT to 443 on the loopback

 

portal may only be accessible from LAN as you can't use the same trick for portal

 

port 5000.png

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 2040 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!