- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-03-2019 10:03 PM - edited 02-06-2019 08:52 PM
Hello,
PAN-OS 8.1.4; GP 4.1.6
I am using only the one VR with dual gateways and ECMP routing enabled with WRR (Weigthed 1/4 (WAN1=50, WAN2=200).
I have one portal configured for WAN2. I have two (2) gateways; one on WAN2 and one on WAN1. When WAN2 is up, I can acces the portal and the gateway on that interface.
When the portal is down (WAN2), and WAN1 up, I expected the client to connect to the second gateway (WAN1) which it does not.
Each of the client's Internet services (WAN1 & WAN2) only have a single public IP address. And they are NATting all traffic in and out to the firewall behind it using private IP addressing.
They have another service listening on TCP 443 (HTTPS). So I need to use a different TCP port for the GP Client.
This I have also configured on my lab PA-VM100 as per the documentation I have found (see below).
The NAT portion of this technique is working to the loopback interfaces if leave the TCP port unchanged (443).
However when I change the port number to any other value (e,g, 10443), it does not work. I cannot browser to access the portal, much less te GP client.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClM1CAK
Any idea how to resolve this issue?
02-04-2019 03:09 AM
Hey @FarzanaMustafa
The GlobalProtect portal is the termination point that holds all the information about all the available gateways and thus, to connect to a gateway you must first be connected to the portal. If the portal is down there's no way you'll ever be able to connect to the gateway.
Regards,
Luke.
01-13-2025 06:54 PM
Id love to know if you ever found a resolution for this. What my gut is telling me, is that this never was solved. From my "observation" on how GP works, if the portal is down, it will attempt to reconnect to the last gateway it was connected to. However, i've got a similar situation as you. My portal and primary gateway exist on a palo pair hosted in Azure. Then, we have a 2nd gateway run from a physical pair in our corp office. I have the azure GW set as the highest in the connection profile, and office GW as the low one. If you simply block the portal access, and disconnect, and reconnect, it will establish a connection. But if you kill the portal and gateway, and try, it will say it's trying to connect to the best GW, which it seems it tries to conenct to the previously connected one, and when that fails, and you try to connect the client again, it then is hung saying the portal isn't accessible.
Basically, it seems you need to have redundant portals, but short of having 2 portal entries on the client side, whats the best way to get to fully redundant?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!