{"id":127,"date":"2022-04-25T07:32:46","date_gmt":"2022-04-25T11:32:46","guid":{"rendered":"https:\/\/pressbooks.bccampus.ca\/paloalto\/?post_type=chapter&#038;p=127"},"modified":"2026-02-18T16:06:08","modified_gmt":"2026-02-18T21:06:08","slug":"remote-access-vpn","status":"publish","type":"chapter","link":"https:\/\/pressbooks.bccampus.ca\/paloalto\/chapter\/remote-access-vpn\/","title":{"raw":"3.2 Remote Access VPN","rendered":"3.2 Remote Access VPN"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\r\n<p class=\"textbox__title\">Learning Objectives<\/p>\r\n\r\n<\/header>\r\n<div class=\"textbox__content\">\r\n<ul>\r\n \t<li>Configure a tunnel interface<\/li>\r\n \t<li>Configure a remote access VPN<\/li>\r\n<\/ul>\r\n<\/div>\r\n<\/div>\r\n<div class=\"textbox\">\r\n\r\n<strong>Prerequisites<\/strong>:\r\n<ul>\r\n \t<li>Setup Zones<\/li>\r\n \t<li>Some interface configuration<\/li>\r\n \t<li>Create a new user<\/li>\r\n \t<li>Create an auth policy<\/li>\r\n \t<li>Policy that allows VPN to Inside<\/li>\r\n \t<li>Policy that allows Outside to VPN<\/li>\r\n \t<li>Knowledge of previous labs<\/li>\r\n<\/ul>\r\n<\/div>\r\n<div class=\"textbox shaded\">\r\n\r\n<strong>Scenario<\/strong>: VPNs aren't just about changing your location like many advertisements say they're for. What it's really used for is to securely access a remote location's resources like your workplace, or even your own home. That is what this lab will focus on. We are going to install GlobalProtect Agent on Kali and then we'll try to reach the Internal through VPN connection.\r\n\r\n<\/div>\r\n\r\n[caption id=\"attachment_278\" align=\"aligncenter\" width=\"990\"]<img class=\"wp-image-278 size-full\" style=\"text-align: initial;font-size: 14pt\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image.png\" alt=\"main scenario\" width=\"990\" height=\"544\" \/> Figure 3.27: Main scenario[\/caption]\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 75px\" border=\"0\"><caption>Table 3.5: Addressing Table<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Device<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Configuration<\/th>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">PaloAlto-1<\/td>\r\n<td style=\"width: 50%;height: 15px\">management: 192.168.0.1\/24\r\nEthernet1\/1: 10.0.0.1\/24\r\nEthernet1\/2: DHCP<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Internal (WordPress)<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">KaliLinux2019.3-1<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: DHCP<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Management<\/td>\r\n<td style=\"width: 50%;height: 15px\">eth0: 192.168.0.2\/24<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 60px\" border=\"0\"><caption>Table 3.6: Zone Configuration<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Zone<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Interface<\/th>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Inside<\/td>\r\n<td style=\"width: 50%;height: 15px\">Ethernet1\/1<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Outside<\/td>\r\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2<\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">VPN<\/td>\r\n<td style=\"width: 50%;height: 15px\">Tunnel.1<\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n<h2>Create a Tunnel Interface<\/h2>\r\nUnder <strong>Network &gt; Interfaces<\/strong> in the Tunnel tab, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_425\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-425 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1.jpg\" alt=\"Creating a Tunnel\" width=\"1026\" height=\"830\" \/> Figure 3.28: Creating a Tunnel[\/caption]\r\n\r\nIn the new window, change the virtual router to default, and the security zone to the VPN zone.\r\n\r\n[caption id=\"attachment_426\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-426 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2.jpg\" alt=\"Tunnel Interface\" width=\"1026\" height=\"830\" \/> Figure 3.29: Tunnel Interface[\/caption]\r\n\r\nThen click <b>OK<\/b>.\r\n<h2>Enable User ACL for a Zone<\/h2>\r\nUnder <strong>Network &gt; Zone<\/strong>, click the VPN zone.\r\n\r\n[caption id=\"attachment_427\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-427 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3.jpg\" alt=\"Create a VPN Zone\" width=\"1026\" height=\"830\" \/> Figure 3.30: Create a VPN Zone[\/caption]\r\n\r\nTick the <strong>Enable user identification<\/strong> box.\r\n\r\n[caption id=\"attachment_428\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-428 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4.jpg\" alt=\"Enable User Identification under VPN Zone\" width=\"1026\" height=\"830\" \/> Figure 3.31: Enable User Identification under VPN Zone[\/caption]\r\n\r\nThen press <strong>OK<\/strong>.\r\n<h2>Generate Certs<\/h2>\r\nUnder <strong>Device &gt; Certificate Management &gt; Certificates<\/strong>, click\u00a0on <b>Generate.<\/b>\r\n\r\n[caption id=\"attachment_429\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-429 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5.jpg\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\" \/> Figure 3.32: Generate a certificate[\/caption]\r\n\r\nConfigure these settings in the new window:\r\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 60px\" border=\"0\"><caption>Table 3.7: Certificate Generation<\/caption>\r\n<tbody>\r\n<tr style=\"height: 15px\">\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameters<\/th>\r\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Certificate Name<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Cert Name Here<\/em><\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Common Name<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>The DHCP IP of Ethernet1\/2<\/em><\/td>\r\n<\/tr>\r\n<tr style=\"height: 15px\">\r\n<td style=\"width: 50%;height: 15px\">Certificate Authority<\/td>\r\n<td style=\"width: 50%;height: 15px\"><em>Tick this box<\/em><\/td>\r\n<\/tr>\r\n<\/tbody>\r\n<\/table>\r\n[caption id=\"attachment_284\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-284 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image.png\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\" \/> Figure 3.33: Generate a certificate[\/caption]\r\n\r\nThen click <strong>Generate<\/strong>.\r\n<h2>Create an SSL\/TLS Service Profile<\/h2>\r\nUnder <strong>Device &gt; Certificate Management &gt; SSL\/TLS<\/strong> Service Profile, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_430\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-430 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6.jpg\" alt=\"Add SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" \/> Figure 3.34: Add SSL\/TLS Service Profile[\/caption]\r\n\r\nIn the new window, add the certificate you generated.\r\n\r\n[caption id=\"attachment_287\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-287 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image.png\" alt=\"Configure SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" \/> Figure 3.35: Configure SSL\/TLS Service Profile[\/caption]\r\n\r\nThen click <b>OK<\/b>.\r\n<h2>Create a GlobalProtect Portal<\/h2>\r\nUnder <strong>Network &gt; GlobalProtect &gt; Portals<\/strong>, then click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_431\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-431 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7.jpg\" alt=\"Add a Portal\" width=\"1026\" height=\"830\" \/> Figure 3.36: Add a Portal[\/caption]\r\n\r\nIn the general tab, set the interface to Ethernet1\/2.\r\n\r\n[caption id=\"attachment_432\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-432 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8.jpg\" alt=\"GlobalProtect Portal Configuration\" width=\"1026\" height=\"830\" \/> Figure 3.37: GlobalProtect Portal Configuration[\/caption]\r\n\r\nIn the authentication tab, select SSL\/TLS profile you created in the previous step, then click <strong>Add<\/strong>.\r\n\r\n[caption id=\"attachment_433\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-433 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9.jpg\" alt=\"Adding SSL\/TLS Profile\" width=\"1026\" height=\"830\" \/> Figure 3.38: Adding SSL\/TLS Profile[\/caption]\r\n\r\nIn the new window, change the authentication profile, then press <strong>OK<\/strong>.\r\n\r\n[caption id=\"attachment_434\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-434 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10.jpg\" alt=\"Adding Authentication Profile\" width=\"1026\" height=\"830\" \/> Figure 3.39: Adding Authentication Profile[\/caption]\r\n\r\nIn the agent tab, in the agent section, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_435\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-435 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11.jpg\" alt=\"Adding the agent\" width=\"1026\" height=\"830\" \/> Figure 3.40: Adding the agent[\/caption]\r\n\r\nIn the internal tab in the Internal gateway, click <b>Add.<\/b>\r\n\r\n[caption id=\"attachment_436\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-436 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12.jpg\" alt=\"Configure Internal Gateway\" width=\"1026\" height=\"830\" \/> Figure 3.41: Configure Internal Gateway[\/caption]\r\n\r\nIn this window, change the Address to select IP, and in the IPv4 box, type in the IP of Ethernet1\/2.\r\n\r\n[caption id=\"attachment_438\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-438 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a.jpg\" alt=\"Set the IP address for Internal Gateway\" width=\"1026\" height=\"830\" \/> Figure 3.42: Set the IP address for Internal Gateway[\/caption]\r\n\r\nPress <b>OK<\/b> twice to get back to the agent tab. Then in the trusted root ca section, add your generated cert, and tick the box to install in local root certificate store.\r\n\r\n[caption id=\"attachment_295\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-295 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image.png\" alt=\"Add the Root CA certificate\" width=\"1026\" height=\"830\" \/> Figure 3.43: Add the Root CA certificate[\/caption]\r\n\r\nThen press <b>OK<\/b>.\r\n<h2>Create a GlobalProtect Gateway<\/h2>\r\nUnder <strong>Network &gt; GlobalProtect &gt; Gateways<\/strong>, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_439\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-439 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14.jpg\" alt=\"Add a Gateway\" width=\"1026\" height=\"830\" \/> Figure 3.44: Add a Gateway[\/caption]\r\n\r\nIn the general tab, set the interface to Ethernet1\/2.\r\n\r\n[caption id=\"attachment_297\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-297 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image.png\" alt=\"GlobalProtect Gateway Configuration\" width=\"1026\" height=\"830\" \/> Figure 3.45: GlobalProtect Gateway Configuration[\/caption]\r\n\r\nIn the Authentication tab, add your <strong>SSL\/TLS<\/strong> profile, then click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_440\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-440 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15.jpg\" alt=\"SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" \/> Figure 3.46: SSL\/TLS Service Profile[\/caption]\r\n\r\nIn the new window, select your authentication profile, then click <b>OK.<\/b>\r\n\r\n[caption id=\"attachment_441\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-441 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16.jpg\" alt=\"Authentication Profile\" width=\"1026\" height=\"830\" \/> Figure 3.47: Authentication Profile[\/caption]\r\n\r\nUnder the agent tab, in tunnel settings, tick the tunnel mode checkbox and select the tunnel you made.\r\n\r\n[caption id=\"attachment_442\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-442 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17.jpg\" alt=\"Tunnel Mode and Interface\" width=\"1026\" height=\"830\" \/> Figure 3.48: Tunnel Mode and Interface[\/caption]\r\n\r\nIn client settings, click <b>Add<\/b>.\r\n\r\n[caption id=\"attachment_443\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-443 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18.jpg\" alt=\"Client Settings\" width=\"1026\" height=\"830\" \/> Figure 3.49: Client Settings[\/caption]\r\n\r\nMake sure the <strong>Any<\/strong> checkbox is ticked on top of the OS category, then press <b>OK<\/b>.\r\n\r\n[caption id=\"attachment_444\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-444 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19.jpg\" alt=\"Select Client as Any\" width=\"1026\" height=\"830\" \/> Figure 3.50: Select Client as Any[\/caption]\r\n\r\nIn client IP pool settings, add an IP pool range of this:\r\n\r\n<span style=\"background-color: #d1d1d1\"><code>172.16.10.1-172.16.10.10<\/code><\/span>\r\n\r\n[caption id=\"attachment_445\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-445 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20.jpg\" alt=\"IP Pool Configuration\" width=\"1026\" height=\"830\" \/> Figure 3.51: IP Pool Configuration[\/caption]\r\n\r\nThen press <b>OK<\/b>. Don't forget to commit the configuration!\r\n<h2>Install the GlobalProtect Client on Kali<\/h2>\r\nOpen up a terminal window and run the following commands:\r\n<div class=\"textbox shaded\"><code>#curl -L https:\/\/drive.google.com\/file\/d\/1dPZNoRPkFop3HdmNOCMqtJqQIA_7W9Fh\/view?usp=drive_link --output GP.deb<\/code>\r\n<code>#sudo dpkg -i GP.deb<\/code>\r\n<code>#globalprotect connect -p [IP of Palo Alto Ethernet1\/2 Here]<\/code><\/div>\r\nWhen connecting, it will show an error about validation. Type in y then press enter.\r\n\r\nIt will also ask for your username and password. Enter the one you created prior.\r\n\r\n[caption id=\"attachment_304\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-304 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image.png\" alt=\"Installing GlobalProtect on Kali Linux\" width=\"1026\" height=\"830\" \/> Figure 3.52: Installing GlobalProtect on Kali Linux[\/caption]\r\n<h2>Test Remote Access VPN<\/h2>\r\nOn Kali, after connecting to GlobalProtect, navigate to the IP of the WordPress Server (Internal).\r\n\r\n[caption id=\"attachment_305\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-305 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" \/> Figure 3.53: Verify your configuration[\/caption]\r\n\r\nIf everything was correct, it should display the WordPress site!","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Configure a tunnel interface<\/li>\n<li>Configure a remote access VPN<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox\">\n<p><strong>Prerequisites<\/strong>:<\/p>\n<ul>\n<li>Setup Zones<\/li>\n<li>Some interface configuration<\/li>\n<li>Create a new user<\/li>\n<li>Create an auth policy<\/li>\n<li>Policy that allows VPN to Inside<\/li>\n<li>Policy that allows Outside to VPN<\/li>\n<li>Knowledge of previous labs<\/li>\n<\/ul>\n<\/div>\n<div class=\"textbox shaded\">\n<p><strong>Scenario<\/strong>: VPNs aren&#8217;t just about changing your location like many advertisements say they&#8217;re for. What it&#8217;s really used for is to securely access a remote location&#8217;s resources like your workplace, or even your own home. That is what this lab will focus on. We are going to install GlobalProtect Agent on Kali and then we&#8217;ll try to reach the Internal through VPN connection.<\/p>\n<\/div>\n<figure id=\"attachment_278\" aria-describedby=\"caption-attachment-278\" style=\"width: 990px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-278 size-full\" style=\"text-align: initial;font-size: 14pt\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image.png\" alt=\"main scenario\" width=\"990\" height=\"544\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image.png 990w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image-300x165.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image-768x422.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image-65x36.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image-225x124.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-24-21-16-57-image-350x192.png 350w\" sizes=\"auto, (max-width: 990px) 100vw, 990px\" \/><figcaption id=\"caption-attachment-278\" class=\"wp-caption-text\">Figure 3.27: Main scenario<\/figcaption><\/figure>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 75px\">\n<caption>Table 3.5: Addressing Table<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Device<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">PaloAlto-1<\/td>\n<td style=\"width: 50%;height: 15px\">management: 192.168.0.1\/24<br \/>\nEthernet1\/1: 10.0.0.1\/24<br \/>\nEthernet1\/2: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Internal (WordPress)<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">KaliLinux2019.3-1<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Management<\/td>\n<td style=\"width: 50%;height: 15px\">eth0: 192.168.0.2\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 60px\">\n<caption>Table 3.6: Zone Configuration<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Zone<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Interface<\/th>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Inside<\/td>\n<td style=\"width: 50%;height: 15px\">Ethernet1\/1<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Outside<\/td>\n<td style=\"width: 50%;height: 15px\">Ethernet1\/2<\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">VPN<\/td>\n<td style=\"width: 50%;height: 15px\">Tunnel.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Create a Tunnel Interface<\/h2>\n<p>Under <strong>Network &gt; Interfaces<\/strong> in the Tunnel tab, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_425\" aria-describedby=\"caption-attachment-425\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-425 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1.jpg\" alt=\"Creating a Tunnel\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem1-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-425\" class=\"wp-caption-text\">Figure 3.28: Creating a Tunnel<\/figcaption><\/figure>\n<p>In the new window, change the virtual router to default, and the security zone to the VPN zone.<\/p>\n<figure id=\"attachment_426\" aria-describedby=\"caption-attachment-426\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-426 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2.jpg\" alt=\"Tunnel Interface\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem2-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-426\" class=\"wp-caption-text\">Figure 3.29: Tunnel Interface<\/figcaption><\/figure>\n<p>Then click <b>OK<\/b>.<\/p>\n<h2>Enable User ACL for a Zone<\/h2>\n<p>Under <strong>Network &gt; Zone<\/strong>, click the VPN zone.<\/p>\n<figure id=\"attachment_427\" aria-describedby=\"caption-attachment-427\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-427 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3.jpg\" alt=\"Create a VPN Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem3-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-427\" class=\"wp-caption-text\">Figure 3.30: Create a VPN Zone<\/figcaption><\/figure>\n<p>Tick the <strong>Enable user identification<\/strong> box.<\/p>\n<figure id=\"attachment_428\" aria-describedby=\"caption-attachment-428\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-428 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4.jpg\" alt=\"Enable User Identification under VPN Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem4-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-428\" class=\"wp-caption-text\">Figure 3.31: Enable User Identification under VPN Zone<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<h2>Generate Certs<\/h2>\n<p>Under <strong>Device &gt; Certificate Management &gt; Certificates<\/strong>, click\u00a0on <b>Generate.<\/b><\/p>\n<figure id=\"attachment_429\" aria-describedby=\"caption-attachment-429\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-429 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5.jpg\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem5-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-429\" class=\"wp-caption-text\">Figure 3.32: Generate a certificate<\/figcaption><\/figure>\n<p>Configure these settings in the new window:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse;width: 100%;height: 60px\">\n<caption>Table 3.7: Certificate Generation<\/caption>\n<tbody>\n<tr style=\"height: 15px\">\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%;height: 15px\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Certificate Name<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Cert Name Here<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Common Name<\/td>\n<td style=\"width: 50%;height: 15px\"><em>The DHCP IP of Ethernet1\/2<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px\">\n<td style=\"width: 50%;height: 15px\">Certificate Authority<\/td>\n<td style=\"width: 50%;height: 15px\"><em>Tick this box<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_284\" aria-describedby=\"caption-attachment-284\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-284 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image.png\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-46-16-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-284\" class=\"wp-caption-text\">Figure 3.33: Generate a certificate<\/figcaption><\/figure>\n<p>Then click <strong>Generate<\/strong>.<\/p>\n<h2>Create an SSL\/TLS Service Profile<\/h2>\n<p>Under <strong>Device &gt; Certificate Management &gt; SSL\/TLS<\/strong> Service Profile, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_430\" aria-describedby=\"caption-attachment-430\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-430 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6.jpg\" alt=\"Add SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem6-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-430\" class=\"wp-caption-text\">Figure 3.34: Add SSL\/TLS Service Profile<\/figcaption><\/figure>\n<p>In the new window, add the certificate you generated.<\/p>\n<figure id=\"attachment_287\" aria-describedby=\"caption-attachment-287\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-287 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image.png\" alt=\"Configure SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-00-52-33-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-287\" class=\"wp-caption-text\">Figure 3.35: Configure SSL\/TLS Service Profile<\/figcaption><\/figure>\n<p>Then click <b>OK<\/b>.<\/p>\n<h2>Create a GlobalProtect Portal<\/h2>\n<p>Under <strong>Network &gt; GlobalProtect &gt; Portals<\/strong>, then click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_431\" aria-describedby=\"caption-attachment-431\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-431 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7.jpg\" alt=\"Add a Portal\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem7-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-431\" class=\"wp-caption-text\">Figure 3.36: Add a Portal<\/figcaption><\/figure>\n<p>In the general tab, set the interface to Ethernet1\/2.<\/p>\n<figure id=\"attachment_432\" aria-describedby=\"caption-attachment-432\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-432 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8.jpg\" alt=\"GlobalProtect Portal Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem8-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-432\" class=\"wp-caption-text\">Figure 3.37: GlobalProtect Portal Configuration<\/figcaption><\/figure>\n<p>In the authentication tab, select SSL\/TLS profile you created in the previous step, then click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_433\" aria-describedby=\"caption-attachment-433\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-433 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9.jpg\" alt=\"Adding SSL\/TLS Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem9-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-433\" class=\"wp-caption-text\">Figure 3.38: Adding SSL\/TLS Profile<\/figcaption><\/figure>\n<p>In the new window, change the authentication profile, then press <strong>OK<\/strong>.<\/p>\n<figure id=\"attachment_434\" aria-describedby=\"caption-attachment-434\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-434 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10.jpg\" alt=\"Adding Authentication Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem10-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-434\" class=\"wp-caption-text\">Figure 3.39: Adding Authentication Profile<\/figcaption><\/figure>\n<p>In the agent tab, in the agent section, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_435\" aria-describedby=\"caption-attachment-435\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-435 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11.jpg\" alt=\"Adding the agent\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem11-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-435\" class=\"wp-caption-text\">Figure 3.40: Adding the agent<\/figcaption><\/figure>\n<p>In the internal tab in the Internal gateway, click <b>Add.<\/b><\/p>\n<figure id=\"attachment_436\" aria-describedby=\"caption-attachment-436\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-436 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12.jpg\" alt=\"Configure Internal Gateway\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem12-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-436\" class=\"wp-caption-text\">Figure 3.41: Configure Internal Gateway<\/figcaption><\/figure>\n<p>In this window, change the Address to select IP, and in the IPv4 box, type in the IP of Ethernet1\/2.<\/p>\n<figure id=\"attachment_438\" aria-describedby=\"caption-attachment-438\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-438 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a.jpg\" alt=\"Set the IP address for Internal Gateway\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem13a-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-438\" class=\"wp-caption-text\">Figure 3.42: Set the IP address for Internal Gateway<\/figcaption><\/figure>\n<p>Press <b>OK<\/b> twice to get back to the agent tab. Then in the trusted root ca section, add your generated cert, and tick the box to install in local root certificate store.<\/p>\n<figure id=\"attachment_295\" aria-describedby=\"caption-attachment-295\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-295 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image.png\" alt=\"Add the Root CA certificate\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-26-39-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-295\" class=\"wp-caption-text\">Figure 3.43: Add the Root CA certificate<\/figcaption><\/figure>\n<p>Then press <b>OK<\/b>.<\/p>\n<h2>Create a GlobalProtect Gateway<\/h2>\n<p>Under <strong>Network &gt; GlobalProtect &gt; Gateways<\/strong>, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_439\" aria-describedby=\"caption-attachment-439\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-439 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14.jpg\" alt=\"Add a Gateway\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem14-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-439\" class=\"wp-caption-text\">Figure 3.44: Add a Gateway<\/figcaption><\/figure>\n<p>In the general tab, set the interface to Ethernet1\/2.<\/p>\n<figure id=\"attachment_297\" aria-describedby=\"caption-attachment-297\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-297 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image.png\" alt=\"GlobalProtect Gateway Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-35-57-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-297\" class=\"wp-caption-text\">Figure 3.45: GlobalProtect Gateway Configuration<\/figcaption><\/figure>\n<p>In the Authentication tab, add your <strong>SSL\/TLS<\/strong> profile, then click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_440\" aria-describedby=\"caption-attachment-440\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-440 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15.jpg\" alt=\"SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem15-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-440\" class=\"wp-caption-text\">Figure 3.46: SSL\/TLS Service Profile<\/figcaption><\/figure>\n<p>In the new window, select your authentication profile, then click <b>OK.<\/b><\/p>\n<figure id=\"attachment_441\" aria-describedby=\"caption-attachment-441\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-441 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16.jpg\" alt=\"Authentication Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem16-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-441\" class=\"wp-caption-text\">Figure 3.47: Authentication Profile<\/figcaption><\/figure>\n<p>Under the agent tab, in tunnel settings, tick the tunnel mode checkbox and select the tunnel you made.<\/p>\n<figure id=\"attachment_442\" aria-describedby=\"caption-attachment-442\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-442 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17.jpg\" alt=\"Tunnel Mode and Interface\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem17-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-442\" class=\"wp-caption-text\">Figure 3.48: Tunnel Mode and Interface<\/figcaption><\/figure>\n<p>In client settings, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_443\" aria-describedby=\"caption-attachment-443\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-443 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18.jpg\" alt=\"Client Settings\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem18-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-443\" class=\"wp-caption-text\">Figure 3.49: Client Settings<\/figcaption><\/figure>\n<p>Make sure the <strong>Any<\/strong> checkbox is ticked on top of the OS category, then press <b>OK<\/b>.<\/p>\n<figure id=\"attachment_444\" aria-describedby=\"caption-attachment-444\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-444 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19.jpg\" alt=\"Select Client as Any\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem19-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-444\" class=\"wp-caption-text\">Figure 3.50: Select Client as Any<\/figcaption><\/figure>\n<p>In client IP pool settings, add an IP pool range of this:<\/p>\n<p><span style=\"background-color: #d1d1d1\"><code>172.16.10.1-172.16.10.10<\/code><\/span><\/p>\n<figure id=\"attachment_445\" aria-describedby=\"caption-attachment-445\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-445 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20.jpg\" alt=\"IP Pool Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20.jpg 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20-300x243.jpg 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20-1024x828.jpg 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20-768x621.jpg 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20-65x53.jpg 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20-225x182.jpg 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/Rem20-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-445\" class=\"wp-caption-text\">Figure 3.51: IP Pool Configuration<\/figcaption><\/figure>\n<p>Then press <b>OK<\/b>. Don&#8217;t forget to commit the configuration!<\/p>\n<h2>Install the GlobalProtect Client on Kali<\/h2>\n<p>Open up a terminal window and run the following commands:<\/p>\n<div class=\"textbox shaded\"><code>#curl -L https:\/\/drive.google.com\/file\/d\/1dPZNoRPkFop3HdmNOCMqtJqQIA_7W9Fh\/view?usp=drive_link --output GP.deb<\/code><br \/>\n<code>#sudo dpkg -i GP.deb<\/code><br \/>\n<code>#globalprotect connect -p [IP of Palo Alto Ethernet1\/2 Here]<\/code><\/div>\n<p>When connecting, it will show an error about validation. Type in y then press enter.<\/p>\n<p>It will also ask for your username and password. Enter the one you created prior.<\/p>\n<figure id=\"attachment_304\" aria-describedby=\"caption-attachment-304\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-304 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image.png\" alt=\"Installing GlobalProtect on Kali Linux\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-45-47-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-304\" class=\"wp-caption-text\">Figure 3.52: Installing GlobalProtect on Kali Linux<\/figcaption><\/figure>\n<h2>Test Remote Access VPN<\/h2>\n<p>On Kali, after connecting to GlobalProtect, navigate to the IP of the WordPress Server (Internal).<\/p>\n<figure id=\"attachment_305\" aria-describedby=\"caption-attachment-305\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-305 size-full\" src=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image.png 1026w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image-300x243.png 300w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image-1024x828.png 1024w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image-768x621.png 768w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image-65x53.png 65w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image-225x182.png 225w, https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-content\/uploads\/sites\/1640\/2022\/04\/2022-04-25-01-50-02-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-305\" class=\"wp-caption-text\">Figure 3.53: Verify your configuration<\/figcaption><\/figure>\n<p>If everything was correct, it should display the WordPress site!<\/p>\n","protected":false},"author":1572,"menu_order":2,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-127","chapter","type-chapter","status-publish","hentry"],"part":123,"_links":{"self":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/127","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/users\/1572"}],"version-history":[{"count":25,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/127\/revisions"}],"predecessor-version":[{"id":1345,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/127\/revisions\/1345"}],"part":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/123"}],"metadata":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/127\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=127"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=127"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=127"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/pressbooks.bccampus.ca\/paloalto\/wp-json\/wp\/v2\/license?post=127"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}