- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-27-2018 05:37 AM
I want to create a IPSec tunnel and use the global protect client to access via VPN our PCI internet network can that be done?
04-27-2018 10:07 AM
Does your security guy want you to utilize IKE2 for the actual PCI tunnel or for the clients connecting to the firewall? good question if I know him he would want both if it can be done.
Your security guy should be happier about utilizing an SSL VPN connection over an IPSec tunnel.
I agree absolutely we need to get rid of x-auth but its hard to get them all off the native client and the cisco client. Even the security guy uses his native client instead of the GP client on his MAC
This simply needs to get disabled. With the Linux client being available there is no reason to continue to utilize X-Auth with GP at all. The security guy should be making this push more than anyone else.
04-27-2018 11:20 AM
Great info.
My plan is to make them use the GP client and that is why I was so glad to see version 4.1 come out but I know there are more types of VPN tunnels that can be created on the PA , IPSec and global protect. I can't use the global protect VPN because there is no IKE2 but quite honestly I don't know how to set up any other kind on the PA. So I need to set up an IPSec VPN tunnel that works with version 4.1 so these same PCI users can VPN into the PCI network and VPN from home into the network. Hope that makes sense
04-27-2018 11:29 AM
Right but you are addressing that by simply forcing them to use the GlobalProtect Agent and turning off X-Auth and leaving the 'Enable IPSec' checkbox along so that IPSec isn't used. This forces the agent to utilize the more secure SSL VPN process.
04-27-2018 12:02 PM
wish it were that easy but I am trying to build a new tunnel to replace the ASA tunnel, not sure what type of tunnel to build
04-27-2018 12:28 PM
B2B can be built using IKEv2, and i am assuming that is what your security guy wants to do too 🙂
you can inform him about the GP's SSL and i am sure he will agree.
~HTH
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!