I have a PAN behind the ADSL modem. ADSL modem is configured in bridge mode.
I configured ethernet1/6 interface to get IP address via PPPoE with a static IP address specification.
But I see the IP address of this interface as dynamic (PPPoE).
When I want to configure SSL-VPN, I can't select etherne1/6 as a gateway interface
How can I solve this problem? Why does PAN consider IP address as dynamic (PPPoE) with a static IP configuration?
in the advance settings there should be an area to set up static ip address for pppoe, if this is configured and you still see the palo alto device showing dynamic please call into support to further investigate.
I made a workaround by configuring an interface1/2 in trust zone as a gateway of SSL-VPN.
And I create a destination NAT for port 8443 on untrust ethernet1 to ethernet1/2 port 443
and create a source NAT for trust zone.
Then I can able to access my internal network. But i think this is not a good solution. I should be able to create a ssl-vpn directly on untrust interface.
I created a ticket about this issue.
Engineering said that SSL-VPN on PPPoE interface is not supported.
Just, I wanted to inform the community.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!