(posted this in the global protect forum, but this seems to get more traffic, and maybe more suggestions, so I moved it here) So I'm about due to retire my old 3050's and upgrade to 3250's - and this time I've convinced management to buy me the global protect subscription by pointing out that the changes in the way it operates after software version 8.1 remove the ability to split-tunnel for remotes, and would add load to the edge - so I win. Previously, I've just run with no license, and run the portal/gateway on the one box without any of the bells and whistles. But what can I do with the subscription license? Things I want to consider. 1. Run two gateways - one for company PC's with pre-login enabled, and one for non-company PC's which just uses the old fashioned way of logging in. Can I do this on the same physical hardware by creating two portals (I have multiple external IP's I can bind to the outside interface of the firewall), or won't that work? 2. Create some kind of jump page or remote access page for users to login to selected apps/services without using the VPN client. Is that what Palo Alto call "clientless VPN"? What other nifty stuff can I do with this new found power? Can someone point me to decent how-to's for making this kind of stuff work? Thanks
... View more