Global protect client to connect using a IPSec tunnel

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global protect client to connect using a IPSec tunnel

L4 Transporter

I want to create a IPSec tunnel and use the global protect client to access via VPN our PCI internet network can that be done?

20 REPLIES 20

Does your security guy want you to utilize IKE2 for the actual PCI tunnel or for the clients connecting to the firewall?  good question if I know him he would want both if it can be done. 

Your security guy should be happier about utilizing an SSL VPN connection over an IPSec tunnel.

I agree absolutely we need to get rid of x-auth but its hard to get them all off the native client and the cisco client. Even the security guy uses his native client instead of the GP client on his MAC

This simply needs to get disabled. With the Linux client being available there is no reason to continue to utilize X-Auth with GP at all. The security guy should be making this push more than anyone else. 

@BPry

Great info.

My plan is to make them use the GP client and that is why I was so glad to see version 4.1 come out but I know there are more types of VPN tunnels that can be created on the PA , IPSec  and global protect. I can't use the global protect VPN because there is no IKE2 but quite honestly  I don't know how to set up any other kind on the PA. So I need to set up an IPSec VPN tunnel that works with version 4.1 so these same PCI users can VPN into the PCI network and VPN from home into the network. Hope that makes sense

@jdprovine,

Right but you are addressing that by simply forcing them to use the GlobalProtect Agent and turning off X-Auth and leaving the 'Enable IPSec' checkbox along so that IPSec isn't used. This forces the agent to utilize the more secure SSL VPN process. 

@BPry

wish it were that easy but I am  trying to build a new tunnel to replace the ASA tunnel, not sure what type of tunnel to build

B2B can be built using IKEv2, and i am assuming that is what your security guy wants to do too 🙂

you can inform him about the GP's SSL and i am sure he will agree.

 

~HTH

@Harshit @BPry

If I didn't already mention i but I think BPry already knows this but I have only two PA's and they are in an HA pair

  • 8393 Views
  • 20 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!