I have a need to implement certificate based login for most of our corporate PC's to Global protect - so they pre-login and get domain scripts etc when the remote users logon.
However, I also have a number of PC's which aren;t corporate owned (and, as such, I can't push certificates to) which still need to be able to login just using username/password interactive logins.
One suggestion I have had is to run two Portals on the one gateway - one configured to run pre-login with certificates, one configured to just wait for username/password.
Has anyone tried this? Is it even remotely possible? Can I run two portals on the same IP address with the different authentication methods?
Any insight appreciated. I'm trying to experiment, but I'm wary of doing it live if I can avoid it.
are you sure that you need a GP Portal License?
As far as i know you'll only need the Portal License when you configure
more than one external Gateway or internal Gateways.
It should be possible to configure two different Portals on one Firewall as long as they have different IPs.
If you have only one external IP you can configure Destination NAT for different Ports to internal Loopback IPs
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!