- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-04-2025 07:29 PM
Having an enormously hard time implementing Global Protect on Azure. No matter what happens, after installing and executing Global Protect on Azure virtual desktop, VPN tunnel 100% severs RDP communication to the Azure virtual desktop.
Had Palo Alto check routing and network and it appears to be sound. Recommendations were: 1) Network =>Global Protect =>Gateways => Authentication (Allow authentication with User credentials or client certificate) changed to Yes (User Credentials or Client certificate required) 2) Network => global Protect => Portals => Agent => Agent config => Pre-Logon Tunnel Rename Timeout (sec) (Windows Only) changed to -1, and 3) Network => Global Protect => Gateways => Agent => Client Settings => Config => Split Tunnel entered the /24 subnet of the client workstation inorder to RDP to the Azure Virtual desktop in the <EXCLUDE> section.
So, far all recommendations are not appearing to work and everytime the tunnel is executed by excluding the /24 subnet that the client workstation is trying to RDP to Azure Virtual desktop, the tunnel but kills the RDP connection. Only way to recover Azure Virtual Desktop is to totally destroy the Virtual Desktop and recreate it. In addition, instead of putting the subnet of where the workstation RDP'ing to the Azure Virtual Desktop, also tried to use 0.0.0.0/0 default gateway as another alternative in the <EXCLUDE> section to no avail.
Any advice and or recommendations would be enormously appreciated!!!!!!
Regards,
09-05-2025 01:37 PM
Can you detail a little bit more what the traffic flow actually looks like? If I understand things properly:
I don't have experience using Azure Virtual Desktop, but just looking at the configuration briefly it looks like your actual session hosts are placed on a traditional VNet. Is there a reason that you aren't just using a tunnel on either a VM-series or a simple VPN Gateway?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!