cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Hi @ccortijo 

The best and simplies solutions would if your Internet Provider is giving you multiple public IP addresses. But such luxury is not very common.

 

Have you checked the following guide - https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGKCA0

I haven't needed to do it myself, but the concept  is the following:
- There is no way to configure GlobalProtect to listen on different port

- You can however create a loopback interface and enable GP on that

- Using NAT and port forwarding you translate your public IP and custom port to the loopback and 443.

- The drawback is that you IPsec/ESP cannot be NATed, and I am not sure if GP can work with NAT-T. Probably that is why in the last screenshot from the link it is shown that GP client is using SSL instead of IPsec.

 

If you have followed above guide, but you can't get GP to work, can you share more details, part of your configuration  and what issues are you facing?

Who rated this post