Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

GlobalProtect on DHCP Interface

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

GlobalProtect on DHCP Interface

L1 Bithead

Hi,


I have configured GlobalProtect on DHCP interface, but for some reason I can't make it work. I don't see GP web page and I cannot connect to it using GP client.
I tried same config, but with static address and it works perfectly.


Can somebody help me to troubleshoot this?

 

 

 

Thank you.

1 accepted solution

Accepted Solutions

L1 Bithead

Hi, i had - seams you are talking about - the same issue, i've used die version 7.0.3. It was not possible to select the IP-address of the DHCP interface in the Portal and Gateway configuration.

 

To solve the issue i created a 1:1 of the DHCP interface to a loopback interface. Portal and Gateway running at this IP address.

 

Hope this is the problem u mentioned.

 

Those guides were very helpfully:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-...

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-Pa...

 

Regards

Andre

View solution in original post

4 REPLIES 4

L5 Sessionator

A few questions:

 1> How are you tring to access the page with domain name or ip address?

 2> Do you have default route pointing towards your gateway?

 

DHCP.png

 

 3> Are you able to ping to the ip address that you got on interface from DHCP server?

 4> Do you have the dns entry for that domain name?

 

If you are able to connect with static ip address then the only change in the GP configuration will be you will not get any ip address in the drop down list while configuring ip address under portal and gateway.

 

Diff.png

 

If you are able to get the portal page then Check the following link

 

https://live.paloaltonetworks.com/t5/General-Topics/PAN-OS-and-Global-Protect-software/m-p/65670#M39...

 

Lets us know if that solved the issue or not.

Hi Pakumar,

 

>1> How are you tring to access the page with domain name or ip address?

I use ip address that I receive from ISP DHCP server on untrusted interface.

 

 2> Do you have default route pointing towards your gateway?

Yes, I have default route for that interface. I use internet from this interface and it works fine.

default_route.jpg

 

3> Are you able to ping to the ip address that you got on interface from DHCP server?

No I don't, even If I put management profile with ping-enable settings on it. But I can ping it if I use another router (not-palo alto).

From firewal are you able to ping from ISP interface to internet?

ping source x.x.x.x host 8.8.8.8

 

Are you using some destination NAT for the IP address that is provided by the ISP? If yes then that traffic will go inside your network.

L1 Bithead

Hi, i had - seams you are talking about - the same issue, i've used die version 7.0.3. It was not possible to select the IP-address of the DHCP interface in the Portal and Gateway configuration.

 

To solve the issue i created a 1:1 of the DHCP interface to a loopback interface. Portal and Gateway running at this IP address.

 

Hope this is the problem u mentioned.

 

Those guides were very helpfully:

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Global-Protect-Gateway-...

https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-GlobalProtect-Portal-Pa...

 

Regards

Andre

  • 1 accepted solution
  • 5730 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!