GP domain: gp.abc.com
PA IP: 192.168.30.110
DNS server: 172.20.30.150
PA只有一個Interface e1/1: 192.168.30.110
首先先設定Local Authentication
Import gp.abc.com的證書和其他ca/intermediate等等的cert
建立及選擇剛才Import的Certicate
e1/1是listen GP interface, 如果有untrust的通常會選擇untrust
SSL/TLS Service Profile選擇剛才建立的GP和建立Local Authentication
加入以下subnet到client的routing table, 可以經由GP進入
內部DNS Server
SSL/TLS Service Profile還是選擇GP
External設定外部連接方法,建議用FQDN, 輸入gp.abc.com
On-demand比較適合大部份用家,需要時才用VPN
再來就是要設定,VPN user可以連接到那裏
GP已經可用
Reference
https://live.paloaltonetworks.com/t5/%E9%85%8D%E7%BD%AE%E5%92%8C%E5%AE%9E%E6%96%BD/globalprotect%E7%9A%84%E8%AF%81%E4%B9%A6%E9%85%8D%E7%BD%AE-ssl-tls-%E5%AE%A2%E6%88%B7%E7%AB%AF%E8%AF%81%E4%B9%A6%E9%85%8D%E7%BD%AE%E6%96%87%E4%BB%B6-%E5%AE%A2%E6%88%B7%E7%AB%AF-%E6%9C%BA%E5%99%A8%E8%AF%81%E4%B9%A6/ta-p/527867
https://entra.microsoft.com/
https://gp.abc.com:443/SAML20/SP
https://gp.abc.com:443/SAML20/SP/ACS
https://gp.abc.com
Download "Federation Metadata XML"這個file
Import剛才的xml
發現問題
暫時的解決方法是unclick這個
再重做剛才的設定
把Entra ID推高, 或者刪除Local
Gateway和Portal都需要改Authentication
增加可以登入的user
現在已經可以使用entra id登入
Reference
https://learn.microsoft.com/zh-tw/entra/identity/saas-apps/palo-alto-networks-globalprotect-tutorial
2FA需要Conditional Access
Users or agents (Preview) -> All users
Target resources -> Select resources -> Select specific resources -> Palo Alto Networks - GlobalProtect
Access controls -> Grant -> Require authentication strength -> Multifactor authentication
Session -> Sign-in frequency -> Periodic reauthentication -> 4 Hours
再加入小許fine tune







































