SNI for GlobalProtect

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
CLIq
L2 Linker

SNI for GlobalProtect

Hi,

 

is there a way for globalprotect to only listen to a specific URL and forward all other FQDNs?

I already have webservers behind the palo listening to specific SNIs and would like to keep it this way.

 

CLIq
L2 Linker

is a "bump" allowed? ^^

FredJD
L0 Member

I also try to do it. I have 3 Palo's both with a GP gateways setup. I try to find the best way, still looking for a better solution.

 https://movieboxpro.info/  https://movie-box.info/  https://cshare.mobi/ 

 

BPry
Cyber Elite

@CLIq,

The firewall natively doesn't support this feature. You can reach out to your SE to get a feature request put in for this to be considered going forward. 

movieboxproappapk
L0 Member

I am following this thread, facing same thing.

RosieRosie
L0 Member

I couldn't solve this problem through the firewall and I still not find an alternative. I'd be grateful for your help.

CLiqr
L0 Member

I used a reverse proxy for the portal which works fine and entered a fqdn in the portal for the gateway...

unfortunately the globalprotect client simply resolves the IP and doesnt pass the SNI so it could be passed through a reverse proxy...
but maybe a clientless connection would work... might try that

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!