Two Global protect Portals on one gateway - possible?

Reply
darren.g
L4 Transporter

Two Global protect Portals on one gateway - possible?

Folks.

I have a need to implement certificate based login for most of our corporate PC's to Global protect - so they pre-login and get domain scripts etc when the remote users logon.

However, I also have a number of PC's which aren;t corporate owned (and, as such, I can't push certificates to) which still need to be able to login just using username/password interactive logins.

One suggestion I have had is to run two Portals on the one gateway - one configured to run pre-login with certificates, one configured to just wait for username/password.

Has anyone tried this? Is it even remotely possible? Can I run two portals on the same IP address with the different authentication methods?

Any insight appreciated. I'm trying to experiment, but I'm wary of doing it live if I can avoid it.

Thanks

Tags (2)

Accepted Solutions
cpainchaud
L4 Transporter

Not on same IP. Each portal needs its own IP.

View solution in original post


All Replies
hshah
L6 Presenter

Hi  Darren,

Two Portal on one Firewall is possible, but you need to buy a license for GP portal.

Regards,

Hardik Shah

cpainchaud
L4 Transporter

Not on same IP. Each portal needs its own IP.

View solution in original post

MarcoLeckel
L3 Networker

Hi Hardik,

are you sure that you need a GP Portal License?

As far as i know you'll only need the Portal License when you configure

more than one external Gateway or internal Gateways.

It should be possible to configure two different Portals on one Firewall as long as they have different IPs.

If you have only one external IP you can configure Destination NAT for different Ports to internal Loopback IPs

Regards

Marco

HULK
L7 Applicator

Hello Marko,

FYI.

GP-license.JPG

Reference DOC: GlobalProtect Configuration Tech Note --- Page No 3

Thanks

MarcoLeckel
L3 Networker

Hi HULK,

is there anything different to my post?

Or do you just want to proof that i am right ?  :smileywink: :smileylaugh:

Regards

Marco

HULK
L7 Applicator

Hello Marco:smileywink: , I just want to prove that you are right. ( With evidence) :smileylaugh:

Thanks

darren.g
L4 Transporter

Thanks. I'm attempting to get this to work on another interface.

Cheers.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!