@BPry Thanks for your reply. The reason I don't want to use utilize the IP address already present on my untrusted interface is because in the documentation: https://docs.paloaltonetworks.com/globalprotect/9-0/globalprotect-admin/get-started/create-interfaces-and-zones-for-globalprotect.html it states, "For added security and better visibility, you can create a separate zone, such as corp-vpn", so that's what I'm trying to do. It could be just me being paranoid, but it feels wonky to have GP on my main Interface and not in a separate zone. As for the loopback, I got nothing on how to make that happen.........
... View more