GlobalProtect, enabling ipsec from outside

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

GlobalProtect, enabling ipsec from outside

L2 Linker

Hi all,

I am trying to enable Global Protect. So far I've been able to connect the client to the firewall successfully. However the remote VPN client cannot talk to inside hosts. But the inside hosts can ping the remote client.

After troubleshooting, I found  IPSec traffic is blocked at the outside interface (which blocks everything). When I enable all incoming traffic on the outside interface the remote client is able to talk to the inside zone.

I've now enabled "IPSec" application group to be passed through the outside interface, however the remote client is still unable to talk to the inside zone. Is there a standard set of applications/services that needs to be allowed on the outside interface for GlobalProtect clients?

Many thanks.

1 accepted solution

Accepted Solutions

you can allow the above said applications, alternatively you can place the tunnel interface in the internal zone that way you need not create any security policies.

View solution in original post

4 REPLIES 4

L5 Sessionator

On the rule that you have enabled "IPSec", please go ahead and add following as well " panos-global-protect, ike, ipsec-esp-udp, panos-web-interface, ssl". This should resolve the issue.Thanks.

you can allow the above said applications, alternatively you can place the tunnel interface in the internal zone that way you need not create any security policies.

L5 Sessionator

Did that resolved your issue? Please do let us know. Thanks.

Putting the tunnel interface on the inside zone fixed the problem.

Opening up the apps on the outside interface did not, however I didn't have much time to troubleshoot this scenario, so it is possible I missed something.

Thanks for the help guys.

  • 1 accepted solution
  • 3825 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!