- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-25-2024 09:52 AM
Hi 🙂
Im looking for solution. I need to configure global protect to:
And im stuck to be honest. Im coming from cisco networking where i can create multiple profiles with separate configurations.
Is it possible to create it on palo with only one GPPortal and one GPGateway?
I configured authentication tab like below and it successfully login ldap users and check for certificate but it dont work for local users. I understand that is because those 2 client authentication methods dont work as i though and i need authentication sequence.
So i made a sequence but now if i set "Allow authentication with user credentials or client certificate" to no (because i want to check ldap user cert) local users cant log in because they dont have cert. I feel little bamboozled 😕
06-25-2024 01:18 PM
Any reason why you're trying to limit yourself to one portal and one gateway? Personally I would recommend having contractors completely separate from your normal users. I isolate them to their own zone completely with a dedicated portal and gateway to utilize going forward. It makes it so I don't have to worry about a misconfiguration granting access to contractors when it shouldn't, and then you don't need to worry about competing authentication settings at all.
06-26-2024 12:04 AM
We have only one public IP address and we didn't want to overcomplicate it too much with loopback interfaces.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!