you probably do not need IKEv2 for global protect, Scenario:1 you already have a anyconnect client, coming in on an ASA, then it routes to a PaloAlto firewall that has a VPN tunnel and the traffic flows through it, If true, you should be able to configure Paloalto to use SSL and then reroute the traffic through VPN (B2B) tunnel. Scenario: 2 you already have a anyconnect client, coming in on an ASA, then it routes to a ASA firewall that has a VPN tunnel (U-Turning the traffic) and the traffic flows through it, If true, you should still be able to configure Paloalto to use SSL and then reroute the traffic to the ASAand eventually VPN (B2B) tunnel, you would just need to make sure routing is set properly on both firewalls, my suggestion would be to use seperate set of pool ip addresses for both. If there is another scneraio, let me know. ~HTH
... View more