Azure Virtual Desktops integration with Global Protect nightmare

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Azure Virtual Desktops integration with Global Protect nightmare

L0 Member

Having an enormously hard time implementing Global Protect on Azure.  No matter what happens, after installing and executing Global Protect on Azure virtual desktop, VPN tunnel 100% severs RDP communication to the Azure virtual desktop.

 

Had Palo Alto check routing and network and it appears to be sound.  Recommendations were: 1) Network =>Global Protect =>Gateways => Authentication (Allow authentication with  User credentials or client certificate) changed to Yes (User Credentials or Client certificate required) 2) Network => global Protect => Portals => Agent => Agent config => Pre-Logon Tunnel Rename Timeout (sec) (Windows Only) changed to -1, and 3) Network => Global Protect => Gateways => Agent => Client Settings => Config => Split Tunnel entered the /24 subnet of the client   workstation  inorder to  RDP to the Azure Virtual desktop in the <EXCLUDE>  section.    

So, far all recommendations are not appearing to work and everytime the tunnel is executed by excluding the /24 subnet that the client workstation is trying to RDP to Azure Virtual desktop, the tunnel but kills the RDP connection.  Only way to recover Azure Virtual Desktop is to totally destroy the Virtual Desktop and recreate it.  In addition, instead of putting the subnet of where the workstation RDP'ing to the Azure Virtual Desktop, also tried to use 0.0.0.0/0 default gateway as another alternative in the <EXCLUDE> section to no avail.

 

Any advice and or recommendations would be enormously appreciated!!!!!!

 

Regards,  

1 REPLY 1

Cyber Elite
Cyber Elite

@wechang,

Can you detail a little bit more what the traffic flow actually looks like? If I understand things properly:

  • You're installing GlobalProtect as an agent on the Azure VDI machines.
  • You have another client machine that is already using GlobalProtect to the same portal/gateway?
  • When you attempt to RDP to the Azure VDI machine (which is connected to GlobalProtect) from a client machine (which is connected to GlobalProtect) you cannot form a VPN session?

 

I don't have experience using Azure Virtual Desktop, but just looking at the configuration briefly it looks like your actual session hosts are placed on a traditional VNet. Is there a reason that you aren't just using a tunnel on either a VM-series or a simple VPN Gateway? 

  • 95 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!