- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-02-2026 07:46 AM
Hello,
We are using globalprotect for users to connect to our network, but recently we have another set of users that we would like to put them on a separate network. We created another profile on the Gateway specifying that if certain users, we have connection with SAML, should receive the IP address of the secondary subnet. We moved this profile to the top, to be the first one. However is not working, they still receiving the IP from the other subnets configured long time ago. if any help, i would appreciate.
#vpngateways #globalprotect
09-02-2026 05:14 PM
Hi @YParreno ,
Can you explain what you mean by creating another profile on the gateway? Do you mean that you created a new client auth profile for these new users and specified the auth profile to be SAML? And then create a Client Agent config profile? Also, for the existing client auth profile, what type of auth are you using there?
09-03-2026 01:05 PM
Hello Jay,
thanks for responding. I meant under GP>Gateways>agent>Client_Settings> i created another client and move it up to the top so it can be checked first. I have it configured to check if the user that connects is x person to give an IP from that IP pool. the other client settings under is for everybody else to use another set of IP addresses(this has always worked fine). ON the GP>portals, authentication profile, it's the same SAML for both client settings.
Just to mentioned this works fine with the original client settings, i connect with the x username no problem, but somehow it's ignoring the first client settings and it's giving me IP address from the second client settings.
thanks again.
YP
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

