global protect multiple portal issue

Reply
L1 Bithead

global protect multiple portal issue

We want to configure Portal level redundancy in Global protect .If we bind 2 IPs of 2 different location firewalls to our portal address then how does clinent interpret the DNS resolution .after how much time client will try on another system 

L4 Transporter

Re: global protect multiple portal issue

Hi @NIRAVK9,

 

You would need a script to automatically modify the DNS record if the 1st site was to go down. You can poll the firewall to see if it is up/interface up using SNMP. 

 

Though you can set the portal cookie to stay for a week on clients so they only need to connect to the portal once every 5-7 days, this is usually enough time to get the portal up and running again if it goes down (RMA/case with ISP etc.).

 

Alternatively you could look at GP in the cloud?

 

https://www.paloaltonetworks.com/products/innovations/globalprotect-cloud-service

 

hope this helps,

Ben

L6 Presenter

Re: global protect multiple portal issue

@bmorris1. Hi..

 

Though you can set the portal cookie to stay for a week on clients so they only need to connect to the portal once every 5-7 days

 

is this in the GP App config,

L1 Bithead

Re: global protect multiple portal issue

@bmorris1thankyou for the response. Whwre can i find the cookie setting? 

 

if i map 2 IPs to portal address,then whether GP client will try to both Ips one by one ??

L4 Transporter

Re: global protect multiple portal issue

@MickBall

 

Yes it is in the GP app config, in the GP portal

 

Untitled.png

@NIRAVK9 I'm not sure on this one as I have never done it myself as I've never needed portal redundancy due the above cookie authentication.

 

A solution may be to allow users to change the portal address and use different portals but the same gateways. GP should connect to the gateway that responds first.

Untitled2.png

 

L6 Presenter

Re: global protect multiple portal issue

if DNS resolves to 2 ip addresses your globalprotect client will only recieve 1.

 

if the portal connection fails then nothing else will happen.

 

if you reconnect GP then it may get the same address or it may get the second address. it's pretty random and probably not a good idea to use this for redundancy.

 

this is known as DNS "round robin"

 

i would still like to know also about the cookie setting.  where is it...

L6 Presenter

Re: global protect multiple portal issue

sorry @bmorris1, just posted after you...

 

 

L1 Bithead

Re: global protect multiple portal issue

BUt isn't this cookie only for authnetication prupose.?

 

or the cookie also saves the gateways sent to client  during previous connect to portal?

L6 Presenter

Re: global protect multiple portal issue

cookie authentication.,,,,,,,

 

i dont think "cookie auth" answers your question but if you use GP with portal auth only that generates a cookie for the gateway auth then you will need to extend this for when your portal fails.

 

 

i don't think the cached portal ever expires. i only say this because i cannot see any info/help/advice.

 

somebody else can jump in if they can advise further.

L1 Bithead

Re: global protect multiple portal issue

Thankyou @bmorris1 .

 

Just to make my question more clearer

 

What i am looking for is  that when my primary portal fails/goes down  then 

 

1) whether client still try to get the gateway from its cache and connect to one of the gateway which was given to it when it last conencted to portal 

 

2) whether thwere is any way at DNS provider end that i can change the IP mapped to portal address to my secondary location address

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!