GlobalProtect on DHCP Interface

Reply
Highlighted
L1 Bithead

GlobalProtect on DHCP Interface

Hi,


I have configured GlobalProtect on DHCP interface, but for some reason I can't make it work. I don't see GP web page and I cannot connect to it using GP client.
I tried same config, but with static address and it works perfectly.


Can somebody help me to troubleshoot this?

 

 

 

Thank you.


Accepted Solutions
Highlighted
L1 Bithead

Hi, i had - seams you are talking about - the same issue, i've used die version 7.0.3. It was not possible to select the IP-address of the DHCP interface in the Portal and Gateway configuration.

 

To solve the issue i created a 1:1 of the DHCP interface to a loopback interface. Portal and Gateway running at this IP address.

 

Hope this is the problem u mentioned.

 

Those guides were very helpfully:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-...

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-Pa...

 

Regards

Andre

View solution in original post


All Replies
Highlighted
L5 Sessionator

A few questions:

 1> How are you tring to access the page with domain name or ip address?

 2> Do you have default route pointing towards your gateway?

 

DHCP.png

 

 3> Are you able to ping to the ip address that you got on interface from DHCP server?

 4> Do you have the dns entry for that domain name?

 

If you are able to connect with static ip address then the only change in the GP configuration will be you will not get any ip address in the drop down list while configuring ip address under portal and gateway.

 

Diff.png

 

If you are able to get the portal page then Check the following link

 

https://live.paloaltonetworks.com/t5/General-Topics/PAN-OS-and-Global-Protect-software/m-p/65670#M39...

 

Lets us know if that solved the issue or not.

Highlighted
L1 Bithead

Hi Pakumar,

 

>1> How are you tring to access the page with domain name or ip address?

I use ip address that I receive from ISP DHCP server on untrusted interface.

 

 2> Do you have default route pointing towards your gateway?

Yes, I have default route for that interface. I use internet from this interface and it works fine.

default_route.jpg

 

3> Are you able to ping to the ip address that you got on interface from DHCP server?

No I don't, even If I put management profile with ping-enable settings on it. But I can ping it if I use another router (not-palo alto).

Highlighted
L5 Sessionator

From firewal are you able to ping from ISP interface to internet?

ping source x.x.x.x host 8.8.8.8

 

Are you using some destination NAT for the IP address that is provided by the ISP? If yes then that traffic will go inside your network.

Highlighted
L1 Bithead

Hi, i had - seams you are talking about - the same issue, i've used die version 7.0.3. It was not possible to select the IP-address of the DHCP interface in the Portal and Gateway configuration.

 

To solve the issue i created a 1:1 of the DHCP interface to a loopback interface. Portal and Gateway running at this IP address.

 

Hope this is the problem u mentioned.

 

Those guides were very helpfully:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-...

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-Pa...

 

Regards

Andre

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!