Can you have 2 Global Protect Portals on the same interface on a VM series

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Can you have 2 Global Protect Portals on the same interface on a VM series

L1 Bithead

Hello,

 

Just wondering if it is possible to configure a new GP portal and gateway on the same interface as an existing GP protect and gateway are configured

 

Thanks in advance !

5 REPLIES 5

L2 Linker

As far as I know, it cannot be possible. Once you use the same interface information for 2 different Portals and Gateways, you will receive these errors while committing the configuration: 

 

Error: GlobalProtect portal 'Portal1' has used dynamic interface ethernet1/1 as GlobalProtect portal 'Portal2'

Error: GlobalProtect gateway 'tunnel.10' has used dynamic interface ethernet1/1 as GlobalProtect gateway 'tunnel.20'

 

If you use non-dynamic interfaces, you will not even see the IP address in the second Portal or Gateway's IP address drow down menu. 

Cyber Elite
Cyber Elite

@scoobyboy,

Not on the same logical interface itself no, but you can create a new loopback interface and use the new loopback interface for the portal and gateway. 

Guys,

What if we have two static IP addresses on the same interface? Is it possible to configure two different portals on the same network interface?

Cheers,

I have 2 different gateways on the same VM interface.  Under the ethernet interface I added a second IP address and used it for the gateway..  So one is x.x.x.x/24 and the other is x.x.x.y 

L1 Bithead

You can not have two portals on the same interface you can create a new loopback interface to configure multiple GPs.

Refer to below KB for more info

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClUhCAK

  • 6820 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!