Configure DHCP reservation on Global Protect user

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Configure DHCP reservation on Global Protect user

L1 Bithead

Hello Community,

 

Is there a way on the PALO ALTO that we can do DHCP reservation while using the Global protect client VPN.

As of now we don't have any DHCP relay on the PALO ALTO. The PALO ALTO is the one providing IP address for the global protect user.

Is there any DHCP expire on the global protect assign IP address?

I found some docs but more on the regedit and on the LDAP serve.

Thanks

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@SamuelCardoz,

You might want to reach out to your SE and have them put together a Feature Request for this capability. I don't recall the FR # at the moment, but there is already one in the system that they'll be able to add your vote to. This is a fairly common request.

If you don't want to use Framed-IP-Address to assign the IP address, then the method that @TomYoung already brought up is really the best method you have available. You could also set the PreferredIP registry key if you're using Windows, but I personally don't like this method and it doesn't guarantee the IP will always be available. 

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hi @SamuelCardoz ,

 

You could try this and see if it works -> https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UkxCAE&lang=en_US%E2%80%A....

 

I am curious.  Why do you want a fixed IP address for the user?  If it is for security policy rules, you can use Source User instead without having to assign a fixed IP address.  If it is for something else, then that may be the way to go.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

Hi @TomYoung 

Good day,

 

We want to do static IP address in order to connect to our system.

In order to connect the Global protect user to our system we need to add there IP address on the system config file along with there computer name. 

Do you have any idea on how we can achieve this setup. We don't want to used LDAP server to assign an IP address or either editing the registry. If there is a way that we make changes on the firewall only.

Thanks 




Cyber Elite
Cyber Elite

Hi @SamuelCardoz ,

 

You're right.  That document is way too complicated.  I just tested this, and it works!

 

  1. Clone your client config under Gateway > Agent > Client Settings.  Add your user only for the Config Selection Criteria.  Put a range with single IP address in for the pool (e.g., 192.168.0.1-192.168.0.1).  The pool has to be a subnet or a range.  Save and move to top.
  2. Change the client config for everyone else to an IP Pool range that excludes the single IP in the other config (e.g., 192.168.0.2-192.168.0.255).

I used a contiguous range of IP addresses for simplicity only.  A completely separate subnet could also be used.

 

Thanks,

 

Tom

 

PS The user name must match exactly to Network > GlobalProtect > Gateways > Remote Users > Primary Username.

Help the community: Like helpful comments and mark solutions.

Cyber Elite
Cyber Elite

@SamuelCardoz,

You might want to reach out to your SE and have them put together a Feature Request for this capability. I don't recall the FR # at the moment, but there is already one in the system that they'll be able to add your vote to. This is a fairly common request.

If you don't want to use Framed-IP-Address to assign the IP address, then the method that @TomYoung already brought up is really the best method you have available. You could also set the PreferredIP registry key if you're using Windows, but I personally don't like this method and it doesn't guarantee the IP will always be available. 

  • 1 accepted solution
  • 6818 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!