{"id":2593,"date":"2022-11-03T18:27:05","date_gmt":"2022-11-03T15:27:05","guid":{"rendered":"https:\/\/artem.services\/?p=2546"},"modified":"2022-11-07T17:43:23","modified_gmt":"2022-11-07T14:43:23","slug":"2593","status":"publish","type":"post","link":"https:\/\/artem.services\/?p=2593&lang=en","title":{"rendered":"Palo Alto VM-Series Firewall: GlobalProtect"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2328\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo.png\" alt=\"\" width=\"2560\" height=\"465\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo.png 2560w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-300x54.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1024x186.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-768x140.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1536x279.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-2048x372.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-954x173.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/09\/palo-alto-logo-1354x246.png 1354w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>Before start configuring GlobalProtect, needs to generate\/<a href=\"https:\/\/artem.services\/?p=2485&amp;lang=en\" target=\"_blank\" rel=\"noopener\">import an SSL certificate<\/a> and create an <strong>SSL\/TLS Service Profile<\/strong>. And also needs an Authentication Profile, you can either create a local user base or use an external one. An example of using <a href=\"https:\/\/artem.services\/?p=2515&amp;lang=en\" target=\"_blank\" rel=\"noopener\">OneLogin<\/a> and <a href=\"https:\/\/artem.services\/?p=2541&amp;lang=en\" target=\"_blank\" rel=\"noopener\">AWS SSO<\/a>.<\/p>\n<h4>Security zone<\/h4>\n<p>First of all, needs to create a security zone for the VPN interface. To do this, go to the &quot;<strong>Network<\/strong>&quot; -&gt; &quot;<strong>Zones<\/strong>&quot; tab and click &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>Set the name, select &quot;<strong>Layer3<\/strong>&quot; as the &quot;<strong>Type<\/strong>&quot; and enable the &quot;<strong>Enable User Identification<\/strong>&quot; option. Leaves everything else by default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2547\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24.png\" alt=\"\" width=\"1588\" height=\"1156\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24.png 1588w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24-300x218.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24-1024x745.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24-768x559.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24-1536x1118.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24-954x694.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-16.52.24-1354x986.png 1354w\" sizes=\"(max-width: 1588px) 100vw, 1588px\" \/><\/p>\n<h4><\/h4>\n<h4><!--more-->Tunnel interface<\/h4>\n<p>Now let&#8217;s create a tunnel, for this we go to the &quot;<strong>Network<\/strong>&quot; -&gt; &quot;<strong>Interfaces<\/strong>&quot; -&gt; &quot;<strong>Tunnel<\/strong>&quot; tab and add a new one.<\/p>\n<ul>\n<li>Number: any number from 1 to 9999<\/li>\n<li>Comment: optional, for faster identification<\/li>\n<li>Virtual Router: <strong>default<\/strong><\/li>\n<li>Security Zone: <strong>vpn-zone<\/strong><\/li>\n<\/ul>\n<p>Leaves everything else by default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2548\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.01.59.png\" alt=\"\" width=\"1394\" height=\"612\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.01.59.png 1394w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.01.59-300x132.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.01.59-1024x450.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.01.59-768x337.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.01.59-954x419.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.01.59-1354x594.png 1354w\" sizes=\"(max-width: 1394px) 100vw, 1394px\" \/><\/p>\n<p>Click &quot;<strong>OK<\/strong>&quot; and check the created interface.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2549\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.08.14.png\" alt=\"\" width=\"1344\" height=\"344\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.08.14.png 1344w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.08.14-300x77.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.08.14-1024x262.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.08.14-768x197.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.08.14-954x244.png 954w\" sizes=\"(max-width: 1344px) 100vw, 1344px\" \/><\/p>\n<h4>Static routes<\/h4>\n<p>Internal networks according to our scheme can be accessed through the &quot;<strong>trust<\/strong>&quot; interface, for this, needs to create 2 static routes.<\/p>\n<p>To do this, go to the &quot;<strong>Network<\/strong>&quot; -&gt; &quot;<strong>Virtual Routers<\/strong>&quot; tab and select the &quot;<strong>default<\/strong>&quot; router.<\/p>\n<p>Go to the &quot;<strong>Static Routes<\/strong>&quot; tab and add a route<\/p>\n<ul>\n<li>Destination: &quot;<strong>10.0.0.0\/8<\/strong>&quot;<\/li>\n<li>Interface: &quot;<strong>ethernet1\/3<\/strong>&quot; (trusted-zone)<\/li>\n<li>Next Hop: &quot;<strong>IP Address<\/strong>&quot; &#8212; &quot;<strong>10.0.13.1<\/strong>&quot;<\/li>\n<li>Admin Distance: &quot;<strong>10<\/strong>&quot;<\/li>\n<li>Metric: &quot;<strong>10<\/strong>&quot;<\/li>\n<\/ul>\n<p>Where &quot;<strong>10.0.13.1<\/strong>&quot; &#8212; AWS gateway for &quot;<strong>GP-TRUST-A<\/strong>&quot; subnet<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2603\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.26.25.png\" alt=\"\" width=\"1188\" height=\"1084\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.26.25.png 1188w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.26.25-300x274.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.26.25-1024x934.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.26.25-768x701.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.26.25-954x870.png 954w\" sizes=\"(max-width: 1188px) 100vw, 1188px\" \/><\/p>\n<p>There is such a moment, in the &quot;<strong>Active-Passive<\/strong>&quot; mode, static routes are synchronized between instances, as well as &quot;<strong>Admin Distance<\/strong>&quot; and &quot;<strong>Metric<\/strong>&quot; are synchronized, so we cannot influence the choice of route for each instance in this way. The route with the lower &quot;<strong>Admin Distance<\/strong>&quot; and &quot;<strong>Metric<\/strong>&quot; will be chosen as the route, and since the &quot;<strong>Next Hop<\/strong>&quot; parameter is required, it may turn out that the instance in AZ A will have a route through AZ B, which will not work. To get around this point, you can use &quot;<strong>Path Monitoring Destination<\/strong>&quot;, the point is the following, we will check the availability of the gateway, and if it is not available, we do not use this route. Thus, on an instance in AZ A, the active route will be through AZ A, and on an instance of AZ B through AZ B, respectively.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2604\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.22.png\" alt=\"\" width=\"950\" height=\"510\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.22.png 950w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.22-300x161.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.22-768x412.png 768w\" sizes=\"(max-width: 950px) 100vw, 950px\" \/><\/p>\n<p>Check the created route and path monitoring.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2605\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.36.png\" alt=\"\" width=\"1190\" height=\"1088\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.36.png 1190w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.36-300x274.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.36-1024x936.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.36-768x702.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-07-at-12.27.36-954x872.png 954w\" sizes=\"(max-width: 1190px) 100vw, 1190px\" \/><\/p>\n<p>Create a second route through AZ B:<\/p>\n<ul>\n<li>Destination: &quot;<strong>10.0.0.0\/8<\/strong>&quot;<\/li>\n<li>Interface: &quot;<strong>ethernet1\/3<\/strong>&quot; (trusted-zone)<\/li>\n<li>Next Hop: &quot;<strong>IP Address<\/strong>&quot; &#8212; &quot;<strong>10.0.23.1<\/strong>&quot;<\/li>\n<li>Admin Distance: &quot;<strong>20<\/strong>&quot;<\/li>\n<li>Metric: &quot;<strong>20<\/strong>&quot;<\/li>\n<\/ul>\n<p>Where &quot;<strong>10.0.23.1<\/strong>&quot; &#8212; AWS gateway for &quot;<strong>GP-TRUST-B<\/strong>&quot; subnet<\/p>\n<p>And also add monitoring for it, as &quot;<strong>Destination IP<\/strong>&quot; we specify &quot;<strong>10.0.23.1<\/strong>&quot;<\/p>\n<h4>GlobalProtect: Portal<\/h4>\n<p>Go to tab &quot;<strong>Network<\/strong>&quot; -&gt; &quot;<strong>GlobalProtect<\/strong>&quot; -&gt; &quot;<strong>Portals<\/strong>&quot; and click &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>&quot;<strong>General<\/strong>&quot; tab<\/p>\n<p>Set the name and specify in the &quot;<strong>Interface<\/strong>&quot; field &#8212; &quot;<strong>ethernet1\/2<\/strong>&quot; (untrusted-zone).<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2551\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18.png\" alt=\"\" width=\"1588\" height=\"872\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18.png 1588w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18-300x165.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18-1024x562.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18-768x422.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18-1536x843.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18-954x524.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.18.18-1354x744.png 1354w\" sizes=\"(max-width: 1588px) 100vw, 1588px\" \/><\/p>\n<p>&quot;<strong>Authentication<\/strong>&quot; tab<\/p>\n<p>Select &quot;<strong>SSL\/TLS Service Profile<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2552\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46.png\" alt=\"\" width=\"1588\" height=\"928\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46.png 1588w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46-300x175.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46-1024x598.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46-768x449.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46-1536x898.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46-954x558.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.22.46-1354x791.png 1354w\" sizes=\"(max-width: 1588px) 100vw, 1588px\" \/><\/p>\n<p>Add &quot;<strong>Client Authentication<\/strong>&quot;<\/p>\n<p>Specify a name and select a profile, in this example, OneLogin is used as authentication.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2553\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.26.39.png\" alt=\"\" width=\"1190\" height=\"918\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.26.39.png 1190w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.26.39-300x231.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.26.39-1024x790.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.26.39-768x592.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.26.39-954x736.png 954w\" sizes=\"(max-width: 1190px) 100vw, 1190px\" \/><\/p>\n<p>Save and check.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2554\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36.png\" alt=\"\" width=\"1588\" height=\"932\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36.png 1588w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36-300x176.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36-1024x601.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36-768x451.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36-1536x901.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36-954x560.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.28.36-1354x795.png 1354w\" sizes=\"(max-width: 1588px) 100vw, 1588px\" \/><\/p>\n<p>&quot;<strong>Agent<\/strong>&quot; tab<\/p>\n<p><span class=\"HwtZe\" lang=\"en\"><span class=\"jCAhz ChMk0b C1N51c\"><span class=\"ryNqvb\">Create agent configuration<\/span><\/span><\/span> &quot;<strong>Agent<\/strong>&quot; -&gt; &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>&quot;<strong>Authentication<\/strong>&quot; tab<\/p>\n<p>Set the name.<\/p>\n<blockquote><p>(<span class=\"HwtZe\" lang=\"en\"><span class=\"jCAhz ChMk0b\"><span class=\"ryNqvb\">optional<\/span><\/span><\/span>)<\/p>\n<p>You can use cookies to avoid double authentication (first to the portal, then to the gateway), or set different cookie lifetimes for the portal and gateway. Read more <a href=\"https:\/\/docs.paloaltonetworks.com\/globalprotect\/9-1\/globalprotect-admin\/authentication\/about-globalprotect-user-authentication\/how-does-the-app-know-what-credentials-to-supply\/cookie-authentication-on-the-portal-or-gateway\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p><\/blockquote>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2555\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23.png\" alt=\"\" width=\"1594\" height=\"944\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23.png 1594w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23-300x178.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23-1024x606.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23-768x455.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23-1536x910.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23-954x565.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-17.33.23-1354x802.png 1354w\" sizes=\"(max-width: 1594px) 100vw, 1594px\" \/><\/p>\n<p>&quot;<strong>External<\/strong>&quot; tab<\/p>\n<p>Add a gateway, for this, in the &quot;<strong>External Gateways<\/strong>&quot; block, click &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>Specify the name and DNS name. Set the region &#8212; &quot;<strong>Any<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2556\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.41.11.png\" alt=\"\" width=\"954\" height=\"926\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.41.11.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.41.11-300x291.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.41.11-768x745.png 768w\" sizes=\"(max-width: 954px) 100vw, 954px\" \/><\/p>\n<p>Set &quot;<strong>Connect Method<\/strong>&quot; to &quot;<strong>On-demand (Manual user initiated connection)<\/strong>&quot;.<\/p>\n<blockquote><p>On-demand &#8212; adds the ability to disable VPN to the client, and when the client starts, it does not automatically connect.<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2557\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56.png\" alt=\"\" width=\"1592\" height=\"964\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56.png 1592w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56-300x182.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56-1024x620.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56-768x465.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56-1536x930.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56-954x578.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.42.56-1354x820.png 1354w\" sizes=\"(max-width: 1592px) 100vw, 1592px\" \/><\/p>\n<p>This completes the portal setup.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2558\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01.png\" alt=\"\" width=\"2488\" height=\"192\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01.png 2488w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01-300x23.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01-1024x79.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01-768x59.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01-1536x119.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01-2048x158.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01-954x74.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.45.01-1354x104.png 1354w\" sizes=\"(max-width: 2488px) 100vw, 2488px\" \/><\/p>\n<h4>GlobalProtect: Gateway<\/h4>\n<p><span class=\"HwtZe\" lang=\"en\"><span class=\"jCAhz ChMk0b\"><span class=\"ryNqvb\">Go to the tab<\/span><\/span><\/span> &quot;<strong>Network<\/strong>&quot; -&gt; &quot;<strong>GlobalProtect<\/strong>&quot; -&gt; &quot;<strong>Gateways<\/strong>&quot; and click &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>&quot;<strong>General<\/strong>&quot; tab<\/p>\n<p>Set the name and specify in the &quot;<strong>Interface<\/strong>&quot; field &#8212; &quot;<strong>ethernet1\/2<\/strong>&quot; (untrusted-zone).<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2560\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53.png\" alt=\"\" width=\"1730\" height=\"664\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53.png 1730w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53-300x115.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53-1024x393.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53-768x295.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53-1536x590.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53-954x366.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.49.53-1354x520.png 1354w\" sizes=\"(max-width: 1730px) 100vw, 1730px\" \/><\/p>\n<p>&quot;<strong>Authentication<\/strong>&quot; tab<\/p>\n<p>Select &quot;<strong>SSL\/TLS Service Profile<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2561\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30.png\" alt=\"\" width=\"1732\" height=\"972\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30.png 1732w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30-300x168.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30-1024x575.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30-768x431.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30-1536x862.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30-954x535.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.51.30-1354x760.png 1354w\" sizes=\"(max-width: 1732px) 100vw, 1732px\" \/><\/p>\n<p>Add &quot;<strong>Client Authentication<\/strong>&quot;.<\/p>\n<p>Specify a name and select a profile, in this example, OneLogin is used as authentication.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2562\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.53.43.png\" alt=\"\" width=\"1386\" height=\"908\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.53.43.png 1386w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.53.43-300x197.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.53.43-1024x671.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.53.43-768x503.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.53.43-954x625.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.53.43-1354x887.png 1354w\" sizes=\"(max-width: 1386px) 100vw, 1386px\" \/><\/p>\n<p>Tab &quot;<strong>Agent<\/strong>&quot; -&gt; &quot;<strong>Tunnel Settings<\/strong>&quot;<\/p>\n<p>Turn on the &quot;<strong>Tunnel Mode<\/strong>&quot; and specify the tunnel interface that we created.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2563\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08.png\" alt=\"\" width=\"1730\" height=\"764\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08.png 1730w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08-300x132.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08-1024x452.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08-768x339.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08-1536x678.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08-954x421.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.56.08-1354x598.png 1354w\" sizes=\"(max-width: 1730px) 100vw, 1730px\" \/><\/p>\n<p>Go to the &quot;<strong>Client Settings<\/strong>&quot; tab and click &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>&quot;<strong>Config Selection Criteria<\/strong>&quot; tab<\/p>\n<p>Set the name, and leave all criteria by default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2564\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.58.51.png\" alt=\"\" width=\"1492\" height=\"1260\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.58.51.png 1492w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.58.51-300x253.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.58.51-1024x865.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.58.51-768x649.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.58.51-954x806.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-18.58.51-1354x1143.png 1354w\" sizes=\"(max-width: 1492px) 100vw, 1492px\" \/><\/p>\n<p>(optional) &quot;<strong>Authentication Override<\/strong>&quot; tab<\/p>\n<p>Check the boxes next to the fields:<\/p>\n<ul>\n<li>Generate cookie for authentication override<\/li>\n<li>Accept cookie for authentication override<\/li>\n<\/ul>\n<p>And specify the certificate for GlobalProtect.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2565\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.00.06.png\" alt=\"\" width=\"1482\" height=\"484\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.00.06.png 1482w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.00.06-300x98.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.00.06-1024x334.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.00.06-768x251.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.00.06-954x312.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.00.06-1354x442.png 1354w\" sizes=\"(max-width: 1482px) 100vw, 1482px\" \/><\/p>\n<p>Tab &quot;<strong>IP Pools<\/strong>&quot; -&gt; &quot;<strong>IP POOL<\/strong>&quot; and click &quot;<strong>Add<\/strong>&quot;. Set the IP addresses that will be issued to VPN clients.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2566\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.03.49.png\" alt=\"\" width=\"1488\" height=\"710\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.03.49.png 1488w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.03.49-300x143.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.03.49-1024x489.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.03.49-768x366.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.03.49-954x455.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.03.49-1354x646.png 1354w\" sizes=\"(max-width: 1488px) 100vw, 1488px\" \/><\/p>\n<p>In the &quot;<strong>Split Tunnel<\/strong>&quot; tab, specify the networks that the VPN server will announce. In this case &quot;<strong>10.0.0.0\/8<\/strong>&quot;. Also, if necessary, you can exclude networks that do not need to be announced.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2567\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.07.38.png\" alt=\"\" width=\"1490\" height=\"902\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.07.38.png 1490w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.07.38-300x182.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.07.38-1024x620.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.07.38-768x465.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.07.38-954x578.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/10\/Screenshot-2022-10-31-at-19.07.38-1354x820.png 1354w\" sizes=\"(max-width: 1490px) 100vw, 1490px\" \/><\/p>\n<p>This completes the gateway setup.<\/p>\n<h4>Security policy<\/h4>\n<p>Now needs to create a security policy for the VPN zone. Go to the &quot;<strong>Policies<\/strong>&quot; -&gt; &quot;<strong>Security<\/strong>&quot; tab and click &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>&quot;<strong>General<\/strong>&quot; tab. Give it a name and check that &quot;<strong>Rule Type<\/strong>&quot; is &quot;<strong>universal (default)<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2569\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02.png\" alt=\"\" width=\"2150\" height=\"758\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02.png 2150w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02-300x106.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02-1024x361.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02-768x271.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02-1536x542.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02-2048x722.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02-954x336.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.02-1354x477.png 1354w\" sizes=\"(max-width: 2150px) 100vw, 2150px\" \/><\/p>\n<p>&quot;<strong>Source<\/strong>&quot; tab. In &quot;<strong>SOURCE<\/strong> <strong>ZONE<\/strong>&quot; needs to add the security zone created for VPN connections, in this case, it&#8217;s &quot;<strong>vpn-zone<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2570\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18.png\" alt=\"\" width=\"2152\" height=\"832\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18.png 2152w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18-300x116.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18-1024x396.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18-768x297.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18-1536x594.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18-2048x792.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18-954x369.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.18-1354x523.png 1354w\" sizes=\"(max-width: 2152px) 100vw, 2152px\" \/><\/p>\n<p>&quot;<strong>Destination<\/strong>&quot; tab. In &quot;<strong>DESTINATION ZONE<\/strong>&quot; needs to add the security zone created for internal networks, in this case, it&#8217;s &quot;<strong>trust-zone<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2571\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34.png\" alt=\"\" width=\"2150\" height=\"826\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34.png 2150w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34-300x115.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34-1024x393.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34-768x295.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34-1536x590.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34-2048x787.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34-954x367.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.34-1354x520.png 1354w\" sizes=\"(max-width: 2150px) 100vw, 2150px\" \/><\/p>\n<p>&quot;<strong>Application<\/strong>&quot; tab. Check that &quot;<strong>Any<\/strong>&quot; is indicated as applications.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2573\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55.png\" alt=\"\" width=\"2148\" height=\"788\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55.png 2148w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55-300x110.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55-1024x376.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55-768x282.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55-1536x563.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55-2048x751.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55-954x350.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.29.55-1354x497.png 1354w\" sizes=\"(max-width: 2148px) 100vw, 2148px\" \/><\/p>\n<p>&quot;<strong>Service\/URL Category<\/strong>&quot; tab<\/p>\n<p>Set &quot;<strong>Any<\/strong>&quot;, as services.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2572\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57.png\" alt=\"\" width=\"2148\" height=\"794\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57.png 2148w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57-300x111.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57-1024x379.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57-768x284.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57-1536x568.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57-2048x757.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57-954x353.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.20.57-1354x501.png 1354w\" sizes=\"(max-width: 2148px) 100vw, 2148px\" \/><\/p>\n<p>&quot;<strong>Actions<\/strong>&quot; tab<\/p>\n<p>Make sure the action is set to &quot;<strong>Allow<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2575\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04.png\" alt=\"\" width=\"2150\" height=\"704\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04.png 2150w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04-300x98.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04-1024x335.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04-768x251.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04-1536x503.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04-2048x671.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04-954x312.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.31.04-1354x443.png 1354w\" sizes=\"(max-width: 2150px) 100vw, 2150px\" \/><\/p>\n<p>Save the security policy and check that it is in front of the default policies.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2574\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41.png\" alt=\"\" width=\"2420\" height=\"308\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41.png 2420w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41-300x38.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41-1024x130.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41-768x98.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41-1536x195.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41-2048x261.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41-954x121.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.21.41-1354x172.png 1354w\" sizes=\"(max-width: 2420px) 100vw, 2420px\" \/><\/p>\n<h4>NAT Policy<\/h4>\n<p>Now needs to create a NAT policy, for this go to the &quot;<strong>Policies<\/strong>&quot; -&gt; &quot;<strong>NAT<\/strong>&quot; tab and click &quot;<strong>Add<\/strong>&quot;.<\/p>\n<p>&quot;<strong>General<\/strong>&quot; tab<\/p>\n<p>Set the name, and leave the rest as default.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2577\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03.png\" alt=\"\" width=\"1590\" height=\"762\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03.png 1590w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03-300x144.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03-1024x491.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03-768x368.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03-1536x736.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03-954x457.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.03-1354x649.png 1354w\" sizes=\"(max-width: 1590px) 100vw, 1590px\" \/>&quot;<strong>Original Packet<\/strong>&quot; tab<\/p>\n<p>&quot;<strong>SOURCE ZONE<\/strong>&quot; &#8212; add a security zone created for VPN connections, in this case, it&#8217;s &quot;<strong>vpn-zone<\/strong>&quot;.<\/p>\n<p>&quot;<strong>Destination Zone<\/strong>&quot; &#8212; select the security zone created for internal networks, in this case, it&#8217;s &quot;<strong>trust-zone<\/strong>&quot;.<\/p>\n<p>&quot;<strong>Destination Interface<\/strong>&quot; &#8212; select the interface in the &quot;<strong>trust-zone<\/strong>&quot;, in this case, it&#8217;s &quot;<strong>ethernet1\/3<\/strong>&quot;.<\/p>\n<p>&quot;<strong>Service<\/strong>&quot;, &quot;<strong>SOURCE ADDRESS<\/strong>&quot; and &quot;<strong>DESTINATION ADDRESS<\/strong>&quot; &#8212; set &quot;<strong>Any<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2578\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47.png\" alt=\"\" width=\"1594\" height=\"790\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47.png 1594w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47-300x149.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47-1024x508.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47-768x381.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47-1536x761.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47-954x473.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.45.47-1354x671.png 1354w\" sizes=\"(max-width: 1594px) 100vw, 1594px\" \/><\/p>\n<p>&quot;<strong>Translated Packet<\/strong>&quot; tab<\/p>\n<p>Source Address Translation:<\/p>\n<ul>\n<li>Translation Type: &quot;<strong>Dynamic IP And Port<\/strong>&quot;<\/li>\n<li>Address Type: &quot;<strong>Interface Address<\/strong>&quot;<\/li>\n<li>Interface: &quot;<strong>ethernet1\/3<\/strong>&quot; (trusted-zone)<\/li>\n<li>IP Address: &quot;<strong>None<\/strong>&quot; (because IP address assigned by DHCP server)<\/li>\n<\/ul>\n<p>Destination Address Translation:<\/p>\n<ul>\n<li>Translation Type: &quot;<strong>None<\/strong>&quot;<\/li>\n<\/ul>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2579\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29.png\" alt=\"\" width=\"1592\" height=\"570\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29.png 1592w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29-300x107.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29-1024x367.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29-768x275.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29-1536x550.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29-954x342.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.46.29-1354x485.png 1354w\" sizes=\"(max-width: 1592px) 100vw, 1592px\" \/><\/p>\n<p>Save and check.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2580\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30.png\" alt=\"\" width=\"2496\" height=\"254\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30.png 2496w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30-300x31.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30-1024x104.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30-768x78.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30-1536x156.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30-2048x208.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30-954x97.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-11.47.30-1354x138.png 1354w\" sizes=\"(max-width: 2496px) 100vw, 2496px\" \/><\/p>\n<h4>GlobalProtect Client<\/h4>\n<p>Go to the &quot;<strong>Device<\/strong>&quot; tab and find the &quot;<strong>GlobalProtect Client<\/strong>&quot; item on the right and download the list of client versions by clicking &quot;<strong>Check Now<\/strong>&quot;.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2582\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38.png\" alt=\"\" width=\"2490\" height=\"1196\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38.png 2490w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38-300x144.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38-1024x492.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38-768x369.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38-1536x738.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38-2048x984.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38-954x458.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.38-1354x650.png 1354w\" sizes=\"(max-width: 2490px) 100vw, 2490px\" \/><\/p>\n<p>&nbsp;<\/p>\n<blockquote><p>If you see a similar message, then you have not completed the license activation. And since BYOL AMI is used, nothing will work without activating the license. Also, if you download the bundle from the Palo Alto support center and import it, you will get an error regarding the license at the activation stage.<\/p><\/blockquote>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2583\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.26.png\" alt=\"\" width=\"1092\" height=\"300\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.26.png 1092w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.26-300x82.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.26-1024x281.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.26-768x211.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-01-at-13.49.26-954x262.png 954w\" sizes=\"(max-width: 1092px) 100vw, 1092px\" \/><\/p>\n<p>After receiving the list of versions, you need to download and install the required version, for example &#8212; the latest. After you have installed it, you need to activate it.<\/p>\n<blockquote><p>Activation is not synchronized and must be performed on both GlobalProtect instances.<\/p><\/blockquote>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2585\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44.png\" alt=\"\" width=\"2492\" height=\"246\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44.png 2492w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44-300x30.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44-1024x101.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44-768x76.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44-1536x152.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44-2048x202.png 2048w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44-954x94.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-10.33.44-1354x134.png 1354w\" sizes=\"(max-width: 2492px) 100vw, 2492px\" \/><\/p>\n<p>It remains to save changes, for this, in the upper right corner, click &quot;<strong>Commit<\/strong>&quot;.<\/p>\n<h4>GlobalProtect: Connection<\/h4>\n<p>Now we go to the IdP portal, in this case, it&#8217;s OneLogin.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2587\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14.png\" alt=\"\" width=\"2018\" height=\"746\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14.png 2018w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14-300x111.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14-1024x379.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14-768x284.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14-1536x568.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14-954x353.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-16.42.14-1354x501.png 1354w\" sizes=\"(max-width: 2018px) 100vw, 2018px\" \/><\/p>\n<blockquote><p>If you set up a local user base, then you need to follow the link:<\/p>\n<p>https:\/\/YOUR_GP_DOMAIN\/global-protect\/getsoftwarepage.esp<\/p>\n<p>Client download page available even without authentication<\/p><\/blockquote>\n<p>&nbsp;<\/p>\n<p>If click on GlobalProtect application, you will be redirected to the client download page.<\/p>\n<p><img loading=\"lazy\" class=\"alignnone size-full wp-image-2588\" src=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13.png\" alt=\"\" width=\"1890\" height=\"1398\" srcset=\"https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13.png 1890w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13-300x222.png 300w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13-1024x757.png 1024w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13-768x568.png 768w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13-1536x1136.png 1536w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13-954x706.png 954w, https:\/\/artem.services\/wp-content\/uploads\/2022\/11\/Screenshot-2022-11-03-at-17.00.13-1354x1002.png 1354w\" sizes=\"(max-width: 1890px) 100vw, 1890px\" \/><\/p>\n<p>After downloading and installing the client as a portal, specify the domain name for GlobalProtect and the credentials configured in the SAML provider.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Before start configuring GlobalProtect, needs to generate\/import an SSL certificate and create an SSL\/TLS Service Profile. And also needs an Authentication Profile, you can either create a local user base or use an external one. An example of using OneLogin and AWS SSO. Security zone First of all, needs to create a security zone &hellip; <a href=\"https:\/\/artem.services\/?p=2593&#038;lang=en\" class=\"more-link\">\u041f\u0440\u043e\u0434\u043e\u043b\u0436\u0438\u0442\u044c \u0447\u0438\u0442\u0430\u0442\u044c<span class=\"screen-reader-text\"> &quot;Palo Alto VM-Series Firewall: GlobalProtect&quot;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1335],"tags":[1899,1901,1905],"_links":{"self":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2593"}],"collection":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2593"}],"version-history":[{"count":4,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2593\/revisions"}],"predecessor-version":[{"id":2607,"href":"https:\/\/artem.services\/index.php?rest_route=\/wp\/v2\/posts\/2593\/revisions\/2607"}],"wp:attachment":[{"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2593"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2593"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/artem.services\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2593"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}