09-22-2021 11:25 AM
GP on the fw is setup and working. I have a group of users i need to isolate from everyone else - most of the time.So if they use the url vpn1.mydomain.com they get IP Pool X and specific X policies. If they use url vpn2.mydomain.com they get IP Pool Y and specific Y policies.
It seems like i should be able to setup multiple portals and gateways on an interface but i want some confirmation before i start working with a production environment.
09-22-2021 03:30 PM
Understood.
09-27-2021 07:21 AM
this sounds possible, i will give it a shot
01-28-2022 09:22 AM
I have different purpose (new certificate with different CN) to create a new/parallel portal&gateway (to keep the change transparent for end user/and to keep easy revert back possibilities in worst case), so when i try to create a new por+gw by adding new pub-IP on same internet interface, using new certificate, using new client iP pool range, i get below error while pushing the policy,
. SSLVPN: Invalid IPv4 pool value: xxxxxxxxxxxxxxxxxxx
. (Module: rasmgr)
. SSLVPN: failed to parse IP pool in tunnel xxxxxxxxxxx
. (Module: rasmgr)
. Parsing GlobalProtect gateway multi user configs failure
. (Module: rasmgr)
. Commit failed
I checked multiple times that there is no overlapping of client subnet that i am using, and subnet value is also perfect, its large enough, tried with /24, /22, but still not sure why its giving above error.
Is it possible to configure two portal/gateway on same interface but with two different pub IPs and different tunnel interface and different client IP ranges ?
01-28-2022 01:54 PM - edited 01-28-2022 01:57 PM
you can't use two ip's on the same interface. Use a loopback interface to achieve your goals.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!