Palo Alto GlobalProtect VPN Configuration [2024 IMPROVED!!!]

Поділитися
Вставка
  • Опубліковано 29 лис 2024

КОМЕНТАРІ • 74

  • @netsums
    @netsums  9 місяців тому

    FREE Palo Alto Cheat Sheet in different formats and further FREE resources: netsums.com/resources

  • @nimolluon3158
    @nimolluon3158 9 місяців тому +1

    great presentation, it is just my preference that should not move the screen around because it is difficult to follow. Again it is just for me. good job!

    • @netsums
      @netsums  9 місяців тому

      Hi. Thank you for the comment and for your feedback! These feedbacks help us a lot to improve the video quality. :)

  • @sx91k
    @sx91k Рік тому +2

    Great explanation, thanks!

    • @netsums
      @netsums  Рік тому

      You're welcome, I'm glad you liked it!

  • @seththomas3194
    @seththomas3194 2 місяці тому +1

    Good Tutorial...updated and accurate! Thanks

    • @netsums
      @netsums  2 місяці тому

      Glad it was helpful, thank you for the feedback.

  • @bjornm.2183
    @bjornm.2183 10 місяців тому +1

    Good Job, Ricardo!

    • @netsums
      @netsums  10 місяців тому

      Thank you, I hope I could help!

  • @zs8850
    @zs8850 6 місяців тому +1

    Great video! Thank you for what you do!

    • @netsums
      @netsums  6 місяців тому

      No worries, I'm glad you liked the video!

  • @_prince_isra_9845
    @_prince_isra_9845 8 місяців тому +1

    Thank you for video. I learned a lot.

    • @netsums
      @netsums  8 місяців тому

      Very nice, I'm glad we could help you 😊

  • @honno7765
    @honno7765 3 місяці тому

    Amazing video. Thank you! I think, after watching it I was able to figure out why I am getting connected to portal but the connection fails at finding the best available gateway. I misconfigured the Agent External part which is crucial to connect to the gateway

    • @netsums
      @netsums  3 місяці тому

      Cool! I'm glad I could help.

  • @JoseMendez-h1y
    @JoseMendez-h1y 8 місяців тому

    Great video, it was very informative. I realize you purchased the certificate from Digicert, but can you show which certificate type you chose and the step by step process to import the certificate? I've seen the self signed certificate process, but that's not quite the same. Again, great video!!

    • @netsums
      @netsums  8 місяців тому

      Thank you. We just bought the cheapest one we found, since it was just for our lab.
      I released a video about 2 weeks ago (Inbound SSL Decryption) where I show how you can import a Let's Encrypt certificate to the firewall, if you're interested. As a result, you get a public certificate for free. :-) But for that you need a Linux server. Take a look there and let me know if that's what you were looking for:
      ua-cam.com/video/HIt65vK2TXI/v-deo.htmlfeature=shared

  • @veerabsc
    @veerabsc 9 місяців тому

    Very good 👍, if you could show how certificates has done for this GP, would be lovely. Thank you for your hard work

    • @netsums
      @netsums  9 місяців тому +1

      Hi. I'm glad you liked the video. Here we bought a certificate for vpn.netsums.com, but there are other videos that we created a Root-CA certificate on the firewall (CA), and used this CA to sign other certificates we generated locally. Could I answer your question? :-)

  • @jaydipparmar5653
    @jaydipparmar5653 10 місяців тому +1

    you explained very well. let me test this in lab

    • @netsums
      @netsums  10 місяців тому

      Cool, I'm glad you liked it. Let me know later if it worked in your lab

    • @jaydipparmar5653
      @jaydipparmar5653 10 місяців тому

      @@netsums Sure, will do. also can you please create one for SSL forward & SSL Inbound decryption.?

    • @netsums
      @netsums  10 місяців тому

      Here a video about SSL Forward Proxy: ua-cam.com/video/UuKcjfQicNw/v-deo.html. I still need to do the one about SSL Inbound, though. I will keep it in mind.

  • @hakimwalugembe9634
    @hakimwalugembe9634 7 місяців тому

    Thanks for the great video, Can you do video for pass-through IPSec traffic, where the Palo Alto Networks firewall is just an intermediate device between two IPSec peers,

    • @netsums
      @netsums  7 місяців тому

      What do you mean exactly? Do you mean site to site VPN?

  • @abhirajdeshmukh273
    @abhirajdeshmukh273 7 місяців тому

    Thank you for this video, I have a quick question, since I have centralized approach to achieve Hub and spoke model in AWS, which allows data flow on only one private interface in Palo Alto but those are divided into 3 sub interfaces(ingress, egress and east - west). Could you please guide in that case how should I proceed the configurations of Global Protect?

    • @netsums
      @netsums  7 місяців тому

      Hi. Do any of the sub interfaces have a public IP? If not, you would have to configure NAT somewhere. If I were you, I think I would configure a loopback address specially for the portal and gateway configuration and configure the address translation from the public IP to this loopback address. Would it be possible? How does it sound for you?

    • @abhirajdeshmukh273
      @abhirajdeshmukh273 7 місяців тому

      @@netsums so neither of these sub interfaces have public IP, however I do have NAT gateway outside of PA. These sub interfaces are plugged in through endpoints for traffic inspection.
      Where do I need to configure these loopback addresses and how should I configure the address translation?

    • @netsums
      @netsums  7 місяців тому

      You configure the loopback addresses under network -> interfaces. I unfortunately cannot help you with the configuration of your gateway NAT on AWS, because it has been a long time I configured one. It should be a static NAT, all packets addressed to the public IP should be forwarded to THE firewall loopback address.
      If it's too complicated, you can also forward to a physical interface. I just think the configuration with the loopback is "cleaner", because you have a dedicated interface for GlobalProtect. Just a personal preference. :-)

  • @pramodkumargangwar5598
    @pramodkumargangwar5598 4 місяці тому

    hi sir I am using Palo Alto VM trail version there is no license, can I perform this practical?

    • @netsums
      @netsums  4 місяці тому

      I'm not sure. Give it a try to see if it accepts the configuration.

  • @konglyhok4343
    @konglyhok4343 10 місяців тому

    Thanks you! So can you show us how to configured with multiple gateway? It would be useful.

    • @netsums
      @netsums  10 місяців тому

      Hi. I will consider it for an upcoming video. Thank you for the request.

  • @Rich-p5o
    @Rich-p5o 2 місяці тому

    Good Video...

  • @samsal073
    @samsal073 4 місяці тому

    Hi , I was trying Verizon home internet and noticed whenever i connect my machine to work via global protec the speed goes really down. Why is that? Is there anything I can do to fix?

    • @netsums
      @netsums  4 місяці тому

      Sorry, I don't think I can help you there. Maybe set your MTU to 1350 or something like this? You can configure it in the portal configuration, under App. Otherwise you could take a look at the GlobalProtect client logs, maybe some errors could point you to the right direction.

    • @samsal073
      @samsal073 4 місяці тому

      @@netsums thanks for the reply. I have seen post about setting the MTU but I have no idea how to do that. Can you guide me where\how I can access the portal config?

    • @netsums
      @netsums  4 місяці тому

      On the firewall, you go to network -> GlobalProtect -> portals. Click on your portal and click on Agent. Click on your agent configuration and select the tab App. There you need to search for MTU (you can use the browser search, it works), if I'm not mistaken, there is only one option with MTU in it.

  • @Bormanb23
    @Bormanb23 6 місяців тому

    Hello, with always on, is there a way to exclude auto connecting to GP when user is in the corporate network?

    • @netsums
      @netsums  6 місяців тому

      Hi. Yes, you're looking for internal gateway. Take a look at this video: ua-cam.com/video/5PvzQ2GoUR0/v-deo.htmlsi=-vB6IKju_5Sz7vXw

    • @Bormanb23
      @Bormanb23 6 місяців тому

      @@netsums sorry that not what I meant what I want is for users not to auto connect to global protect if they are sitting in the office I only want them to order. Connect to Global protect when they go home.

    • @netsums
      @netsums  6 місяців тому

      The only way I know around this problem is to use the internal host detection that I show in this video.

  • @Tyler-k9b3f
    @Tyler-k9b3f Рік тому

    I wonder how NAT applies to this? the portal URL is typically public IP? this just requires DNS record of the public facing IP on the firewall?

    • @netsums
      @netsums  11 місяців тому +1

      If you have a public IP for your portal, you don't need NAT. You said it correctly, it is typically like this, but not a requirement. You can have a private IP for your portal, as I have in my lab, and still make it reachable from the Internet through a NAT device doing destination NAT.

    • @Tyler-k9b3f
      @Tyler-k9b3f 11 місяців тому

      @@netsumsthank you very much for the response. I recently tried configuring a gp vpn on a client's FW in which they had an existing gp vpn tunnel but wanted a second...i was creating the second GP VPN using their public IP that they use for the existing GP VPN. This caused users to redirect. Do you know off the top of your head by chance why that is? I thought the packet would reach its final destination (the FW) and would get to the code and go to the correct Portal and GW(?). Our new plan is to use a spare public IP they have for the new tunnel.

    • @netsums
      @netsums  11 місяців тому

      I would strongly recommend you to use the second IP for the other portal, I don't think Palo Alto supports two portals sharing the same interface. Why do you need a new portal, anyway? Different authentication methods?

    • @netsums
      @netsums  11 місяців тому

      When you say new tunnel, do you mean new GlobalProtect Gateway? If I were you, I would configure second portal and second gateway sharing the same public IP. The tunnel interface doesn't need an IP address.

    • @Tyler-k9b3f
      @Tyler-k9b3f 11 місяців тому

      @@netsums thank you again for your response sir. The client needs a second GP VPN Tunnel because they want to authenticate with corp laptops with certificate, they have an existing GP VPN tunnel for personal devices.
      I am going to work with the client in about two hours from now to configure it up. The plan is to use their second public IP for the new GP VPN Tunnel. Only thing I'm unsure of now is how routing and NAT will work with this but I'm looking into it now and think I can figure it out on the fly, hopefully, when I hop on the call with them to see how their current is configured.

  • @bryanthompson696
    @bryanthompson696 10 місяців тому +2

    good video thank you

    • @netsums
      @netsums  10 місяців тому

      Glad you enjoyed it!

  • @reginaldoredondo
    @reginaldoredondo 10 місяців тому

    hello my friend.
    I have a problem in my environment that, every time the user logs into the internal environment, global protect closes the connection and the client cannot access the internal network. It's as if global protect blocked access.
    How can I resolve this situation? can you help me?

    • @netsums
      @netsums  10 місяців тому

      Hi. I am not sure I understood your problem. Do you have GlobalProtect setup with internal gateway? What does the log from the GlobalProtect client say (under settings -> troubleshooting)? I would suggest to start with the event log (I think it's called pan_gp_event.log).

  • @RayAlejandroGaviriaAlegria
    @RayAlejandroGaviriaAlegria 9 місяців тому

    tks for this video, its similar configuration for android user ?

    • @netsums
      @netsums  9 місяців тому

      Hi. Yes, it is. Just be careful that for android you need the GlobalProtect Gateway license.

  • @AbhiGangwar-wv1vj
    @AbhiGangwar-wv1vj 6 місяців тому

    Hi, it's a informative video, but my question is how to ping global protect user to outside server. like 1 on premise server installed in India and second server install in US. site A and Site B both side configured ip sec tunnel (site to site VPN), in my case global protect user not able to ping US server. could you please provide the solution.

    • @netsums
      @netsums  6 місяців тому

      There are many reasons for the connection not to be working. But I would start with verifying if the firewall in US can route the global protect network. If yes, I would verify if the encryption domain in the s2s tunnel is encrypting the global protect traffic going to the US servers. Do you see the traffic arriving in US or not?
      I am assuming the global protect user is connecting to a gateway in India.

  • @sridharbvnl2101
    @sridharbvnl2101 11 місяців тому +2

    awesome

    • @netsums
      @netsums  11 місяців тому

      I'm glad you liked it. 👍

  • @VortexRiddle
    @VortexRiddle 2 місяці тому

    Can we use wildcard certificate for multiple gateway ?

    • @netsums
      @netsums  2 місяці тому

      Yes, it should not be a problem.

  • @seanbyrne960
    @seanbyrne960 7 місяців тому

    thank you -- the software will not accept my tunnel interface -- "invalid tunnel reference" in validate commit

    • @netsums
      @netsums  7 місяців тому

      Strange. Are you using Panorama for the configuration? If yes, are your gateway and tunnel configurations in different templates?

    • @seanbyrne960
      @seanbyrne960 7 місяців тому

      @@netsums yes I am using Panorama for this deployment -- there are two existing GP Portals & Gateways -- the logs show only one template --thank you

    • @seanbyrne960
      @seanbyrne960 7 місяців тому

      does your training course cover Panorama deployments & configuration ?

    • @netsums
      @netsums  7 місяців тому

      Take a look in the template stack to see if everything is there, the gateways, the tunnels and the virtual routers, if you're still having problems.
      And yes, the course I'm building will cover templates and device groups deployment. :-)

    • @seanbyrne960
      @seanbyrne960 7 місяців тому

      @@netsums the interfaces , gateways and tunnels are all part of the same template stack

  • @Alex-un5tl
    @Alex-un5tl 11 місяців тому

    can you make one for ipv6 as well please?

    • @netsums
      @netsums  11 місяців тому

      That's a good suggestion! I'll keep this in mind, thanks!

  • @JakirHossene-j4f
    @JakirHossene-j4f 2 місяці тому

    Thomas Matthew Rodriguez Eric Lewis Sandra

  • @KristaWedwick-s5t
    @KristaWedwick-s5t 2 місяці тому

    Jones Sharon Davis Daniel Young George