- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-23-2023 11:52 AM
Hi @ccortijo
The best and simplies solutions would if your Internet Provider is giving you multiple public IP addresses. But such luxury is not very common.
Have you checked the following guide - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGKCA0
I haven't needed to do it myself, but the concept is the following:
- There is no way to configure GlobalProtect to listen on different port
- You can however create a loopback interface and enable GP on that
- Using NAT and port forwarding you translate your public IP and custom port to the loopback and 443.
- The drawback is that you IPsec/ESP cannot be NATed, and I am not sure if GP can work with NAT-T. Probably that is why in the last screenshot from the link it is shown that GP client is using SSL instead of IPsec.
If you have followed above guide, but you can't get GP to work, can you share more details, part of your configuration and what issues are you facing?