Тёмный

GlobalProtect Gateway Selection (Multi-Gateway Configuration) [2024] 

NETSums
Подписаться 3,5 тыс.
Просмотров 2,7 тыс.
50% 1

Опубликовано:

 

28 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 28   
@netsums
@netsums 8 месяцев назад
FREE Palo Alto Cheat Sheet in different formats and further FREE resources: netsums.com/resources
@supriyochatterjee4095
@supriyochatterjee4095 9 месяцев назад
Excellent, thanks a lot Sir, wish to see the entire series on Palo Alto Firewall configuration, implementations on AWS and VMWARE VMC Cloud integrated network soon
@netsums
@netsums 8 месяцев назад
I will try to do it soon
@clementcolombier4215
@clementcolombier4215 4 месяца назад
Every usefull things to know, thanks ! Shame that on Prisma Access you can't modify the priority !
@netsums
@netsums 4 месяца назад
Thank you! If you're configuring Prisma Access using Panorama, you are able to change the portal configuration in the template Mobile_User_Template (under Network). There you can configure the Gateway priorities. Or did you mean using Strata Cloud Manager?
@netsums
@netsums 4 месяца назад
You're right, I meant location, not gateway. Funny, I have a client that has prisma access enterprise, and I was sure you could configure the location priorities on Panorama, under network -> portal. But again, I don't have much experience with prisma access. :-)
@freddycalderon9092
@freddycalderon9092 2 месяца назад
Great way of explaining it but would be better if you could do a tutorial step by step on configuring this option. For example, how to assign a gateway to a dual ISP.
@netsums
@netsums 2 месяца назад
Hi. I will keep that in mind, thanks!
@shi7am
@shi7am 12 дней назад
I also would like this. how to choose a gateway on the 2nd ISP
@netsums
@netsums 8 дней назад
You could allow the users to choose the gateways, would it be a solution for your environment? Or you set the priority of the second gateway to lowest, so that clients only connect to it if the first gateway or ISP is down.
@RayAlejandroGaviriaAlegria
@RayAlejandroGaviriaAlegria 9 месяцев назад
hi, i love your videos, i have a question, what its the differences between internal gateway and external gateway and its usages
@netsums
@netsums 9 месяцев назад
Hi. Thank you, I'm glad you like the videos. Regarding your question, external gateways provide remote access to your network. The internal gateways are usually implemented to gather User-IP mappings from people already inside your network.
@edmundsiew3292
@edmundsiew3292 8 месяцев назад
Hi.. I am also very keen to know more about Internal gateway, its use cases, what other components required to work with the Internal gateway and how to implement. Thanks a lot
@netsums
@netsums 8 месяцев назад
Hi, thank you for the suggestion. Since there is interest from you guys, we will be making a video soon about internal gateway.
@Leokev123
@Leokev123 2 месяца назад
Can I check if we are configuring 2 gateway, then does both WAN ip be on the same VR?
@netsums
@netsums 2 месяца назад
I'm not sure I understand your question. It doesn't matter if the routes to the gateways are configured on the same VR or not, the important thing is that the clients are able to reach the gateways.
@Leokev123
@Leokev123 2 месяца назад
@netsums thanks! Anyway are we able to do Dual ISP/gateway using one portal? So they can do a auto failover
@netsums
@netsums 2 месяца назад
If a client cannot connect to the first gateway, it tries the second one. So with dual ISP, it would be no problem. The only problem there is the GlobalProtect Portal. Usually a client saves the last configuration it downloaded from the portal. But if a client is connecting for the first time, and the portal is not available, the client won't be able to connect. For a portal redundancy you would probably need to setup DNS with some sort of monitoring, if you want an automatic solution.
@Leokev123
@Leokev123 2 месяца назад
@@netsums I configured path monitoring in the VR for both ISP.
@르브론시몬스
@르브론시몬스 8 месяцев назад
I would like to ask you to set up and teach Decryption SSL Inbound Inspection.
@netsums
@netsums 8 месяцев назад
Hi. Thank you, that's a good suggestion, I will have to implement it for a customer soon. I will put it in my video list. :-)
@rajatrajat5435
@rajatrajat5435 9 месяцев назад
Hi. I have one query. Lets say if portal and gateway is on the same firewall and our firewall is down then how can clients connect to Global protect vpn. I am trying to rectify it if the portal is down because the firewall is down then how clients will get info about gateways n all?
@netsums
@netsums 8 месяцев назад
Hi, sorry for the late reply. You are right, you need both portals and gateways to be reachable. In theory, if the portal is not reachable, the GlobalProtect app would use a cached portal configuration, if available, and try to connect to a gateway (I haven't tried it in practice yet). One possibility would be to have a High Availability firewall pair. Another one would be to use DNS to balance the load for you with firewalls in different sites.
@konglyhok4343
@konglyhok4343 9 месяцев назад
Hi, Can we deploy the url access without input in the portal app?
@netsums
@netsums 8 месяцев назад
Hi, if I understood you correctly, you would like to access the gateway directly. I think it's only possible if the portal is not accessible. In this case, the GlobalProtect app should use cached portal configuration and try to connect to the gateway directly.
@smakersify
@smakersify 9 месяцев назад
Hi there, can you do multi isp configuration, on both active or active passive cheers
@netsums
@netsums 9 месяцев назад
Hi. I'll take a look at it, I need to see how I can do it in my lab. Did you mean with static routes?
@smakersify
@smakersify 9 месяцев назад
That would be awesome! thank you. Yes two ISP's, static routes, maybe use case of ECMP? @@netsums
Далее
GlobalProtect Internal Gateway with SAML/OKTA [2024]
19:51
Random Emoji Beatbox Challenge #beatbox #tiktok
00:47
Palo Alto URL Filtering and URL Categories
15:48
Просмотров 4,8 тыс.
Palo Alto GlobalProtect Clientless VPN [2024]
26:07
Просмотров 4,4 тыс.
Palo Alto GlobalProtect with Pre-Logon [2024]
38:59
Просмотров 15 тыс.
Microsoft WSUS - The Beginning of the End
10:33
Просмотров 37 тыс.