Documentation for LSVPN deployments

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Documentation for LSVPN deployments

L4 Transporter

Does anyone have access to, pointers to, or stashes of better documentation for how LSVPN works?  Something along the lines of "best practices" for configuring routing for the satellites?  Or with "big picture" information on how all the pieces work together?


The GlobalProtect Administration Guide and the PanOS Admin Guide show you all the nitty-gritty for configuring the bits on the firewalls, but it doesn't really give you a good sense of how the pieces mesh into a unified whole.


We have a working GlobalProtect setup at work with multiple Portals, multiple Gateways, authenticating using local users and LDAP groups.  All of that is easy to configure and understand, and the setup we're using is extensible to other Gateways as/when needed.


Just did my first LSVPN setup, and nothing about it was easy to do, especially around how routing in VRs on the Satellite interact with Access Routes and Route Filtering on the Gateway.  And there's no information that I can find anywhere for how to force the Satellite to download a new configuration from the Gateway when changes are made.  I'm fairly certain that my setup is not optimal, but I can't find any information on how to improve it.


So, does anyone have a secret stash of LSVPN "big picture" documentation they'd be willing to share?

  • 0 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!