Global Protect Behind NAT

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Global Protect Behind NAT

L0 Member

I have a PA-800 with global protect configured in an internal network. A 1to1 NAT has been setup to map a public IP address to the internal IP address of the external interface of the PA. The 1to1 NAT is on a Cisco ASA5508X with direct passthrough on 443. I set the same internal IP address on the portal and the gateway. When authenticating from the internet, I get to the portal and enter my credentials, it then pushes down a gateway address which is the internal IP address and for obvious reasons fails to setup the tunnel.

 

I thought the solution would be to connect to the PA from a host in the internal network which can access that internal IP, and via the management interface, change the gateway local IP, from the internal IP address to the public IP address. However, when I try to change the gateway IP from the internal IP to the public IP it fails to allow me to change that setting. Is this because I've connected via global protect to make this config change? Could there be any other reason I can't change the local IP on the gateway?

 

Thanks in advance for any help.

1 accepted solution

Accepted Solutions

L0 Member

Found the solution. The external gateway in the client configuration of the global protect portal was the part that needed to have a public IP. See the following article; https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKHCA0

View solution in original post

1 REPLY 1

L0 Member

Found the solution. The external gateway in the client configuration of the global protect portal was the part that needed to have a public IP. See the following article; https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClKHCA0

  • 1 accepted solution
  • 5513 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!