Duplicated IP for different Users

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Duplicated IP for different Users

L0 Member

Hi team

I'm currently having an issue with GLOBAL PROTECT VPN users whose IP has been duplicated, as showed in the next picture:

 

DanielPaz_0-1710274242054.png

As you can see, there is no big time difference between the log generated for the user sprbun\johnfc and the user sprbun\norac

 

I have configured two gateways and this problem is happening when two different users (like in this case) are connected to different gateways. This situation has become regular. 

 

When the problem was occurring, I checked the ip asigned to each user from cli with these commands:

show global-protect-gateway current-user

show user ip-user-mapping all

 

and this is the information that I see:

 

DanielPaz_1-1710274470327.png

 

DanielPaz_2-1710274494198.png

 

From remote users in the gateway this is what I see:

 

DanielPaz_3-1710274883250.png

DanielPaz_4-1710274907994.png

 

I don´t know what could it be, if you could suggest me some troubleshooting guide or any advice I would appreciate it. 

 

Thanks.

 

1 REPLY 1

Cyber Elite
Cyber Elite

Hi!

If I understand your issue correctly, you're using the same IP pool on both gateways?

Its best to use a different pool on each gateway else you'll inevitably run into IP conflicts like you illustrate in your post (pool usage is not synced between the gateways, they're treated as independent 'networks')

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 340 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!