GlobalProtect Gateway behind reverse proxy

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect Gateway behind reverse proxy

L1 Bithead

Is there a way to put the globalprotect gateway behind a reverse proxy for sslvpn only?
I know that technically you can just NAT to the gateway but it is wanted to put the gateway behind a reverse proxy and not use ipsec, only sslvpn.
When I try this, the globalprotect app is allowed but the connection fails nonetheless. I assume this is because the reverse proxy is basically breaking open the connection and in this case is the "meddler in the middle" and is simply not possible because of this?!?

2 REPLIES 2

Cyber Elite

Is the intent to disable IPSec in favor of SSL, because you can simply set that in the GlobalProtect gateway:

 

reaper_1-1776674522461.png

 

It sounds like your reverse proxy may be changing things in the payload of the TLS connection, could it be set to passthrough and not interfere/decrypt ?

 

Tom Piens
PANgurus - Strata & Prisma Access specialist

intent is to allow globalprotect through port 443 as sslvpn in most guest or public networks is not blocked but there is no separate IP
problem is that a reverse proxy is already in place on the only IP
configuring the proxy as stream proxy and then forwarding all but that one SNI to another loopback IP address of the reverse proxy is unfortunately not an option and it seems there is no other option globalprotect likely intentionally doesnt not establish the tunnel if this is detected

  • 397 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!