{"id":1521,"date":"2026-09-13T15:11:44","date_gmt":"2026-09-13T09:41:44","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/palo-alto-globalprotect-configuration\/"},"modified":"2026-09-30T14:57:50","modified_gmt":"2026-09-30T09:27:50","slug":"palo-alto-globalprotect-configuration","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-globalprotect-configuration\/","title":{"rendered":"Palo Alto GlobalProtect Configuration with a Remote User Example"},"content":{"rendered":"<p>Securing enterprise remote access requires a robust VPN solution that enforces strict authentication, seamless client connectivity, and granular access controls. A standard <strong>Palo Alto GlobalProtect configuration<\/strong> allows organizations to terminate remote worker connections directly onto the firewall. This setup applies continuous threat prevention, user-based policies, and centralized logging to all remote traffic.<\/p>\n<p>In this tutorial, you will learn how to build a complete Palo Alto GlobalProtect configuration from scratch. We will walk through certificate deployment, SSL\/TLS profiles, tunnel interfaces, portal and gateway setup, security policies, and verification techniques using both the Web Interface and the PAN-OS Command Line Interface (CLI).<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>An enterprise engineering firm, ExampleCorp, requires secure access for remote systems engineers connecting to critical internal network resources. Remote employees work offsite and must access corporate applications residing in the internal application subnet.<\/p>\n<p>To meet compliance and security mandates, ExampleCorp requires:<\/p>\n<ul>\n<li>Encrypted transport using modern TLS\/IPsec protocols.<\/li>\n<li>User authentication against an internal authentication profile.<\/li>\n<li>Split tunneling to route corporate traffic (<code>10.10.0.0\/16<\/code>) through the encrypted tunnel while sending standard internet traffic out the local network.<\/li>\n<li>Strict security policies restricting remote user access to authorized corporate zones only.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The following diagram illustrates the logical path of the remote client connecting across the public internet to the firewall&#8217;s GlobalProtect Portal and Gateway, terminating onto a virtual tunnel interface mapped to a dedicated security zone.<\/p>\n<pre><code>\n+-------------------------+\n|  Remote Client          |\n|  IP: 198.51.100.50 (Lab)|\n+------------+------------+\n             |\n             | SSL\/IPsec Tunnel (Public Internet)\n             v\n+------------+------------+\n| Interface: ethernet1\/1  | (Zone: Untrust, IP: 203.0.113.10)\n| Palo Alto Firewall      |\n| GlobalProtect Portal &amp;  |\n| Gateway                 |\n+------------+------------+\n             |\n             | Internal Virtual Interface: tunnel.1\n             v (Zone: Remote-VPN, Assigned IP Pool: 10.200.1.0\/24)\n+------------+------------+\n| Internal Security Zone  |\n| Interface: ethernet1\/2  | (Zone: Trust, IP: 10.10.1.1\/24)\n+------------+------------+\n             |\n             v\n+------------+------------+\n| Corporate Resources     |\n| Subnet: 10.10.0.0\/16    |\n+-------------------------+\n<\/code><\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The table below details the example network parameters, hostnames, and interface configurations used throughout this guide. Production deployments must adapt these lab values to match organizational subnets and naming conventions.<\/p>\n<table>\n<thead>\n<tr>\n<th>Object \/ Component<\/th>\n<th>Type \/ Identifier<\/th>\n<th>Lab \/ Example Value<\/th>\n<th>Purpose<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>External Interface<\/td>\n<td>Physical (ethernet1\/1)<\/td>\n<td>203.0.113.10\/24<\/td>\n<td>Terminates public Portal and Gateway connections (Untrust Zone)<\/td>\n<\/tr>\n<tr>\n<td>Internal Interface<\/td>\n<td>Physical (ethernet1\/2)<\/td>\n<td>10.10.1.1\/24<\/td>\n<td>Connects to corporate local area network (Trust Zone)<\/td>\n<\/tr>\n<tr>\n<td>Tunnel Interface<\/td>\n<td>Logical (tunnel.1)<\/td>\n<td>Unnumbered (VR: default)<\/td>\n<td>Logical termination point for GlobalProtect client VPN traffic<\/td>\n<\/tr>\n<tr>\n<td>VPN Security Zone<\/td>\n<td>Layer 3 Zone<\/td>\n<td>Remote-VPN<\/td>\n<td>Dedicated security zone for tunnel.1 interface<\/td>\n<\/tr>\n<tr>\n<td>Client IP Pool<\/td>\n<td>IP Subnet Range<\/td>\n<td>10.200.1.10 &#8211; 10.200.1.250<\/td>\n<td>Dynamic address pool assigned to connected remote clients<\/td>\n<\/tr>\n<tr>\n<td>Split Tunnel Route<\/td>\n<td>IP Subnet<\/td>\n<td>10.10.0.0\/16<\/td>\n<td>Internal destination network routed through the VPN tunnel<\/td>\n<\/tr>\n<tr>\n<td>Portal \/ Gateway FQDN<\/td>\n<td>DNS Name<\/td>\n<td>gp.example.com<\/td>\n<td>External address used by GlobalProtect App clients<\/td>\n<\/tr>\n<tr>\n<td>Lab Test User<\/td>\n<td>User Account<\/td>\n<td>vpnuser1<\/td>\n<td>Test account defined in authentication profile<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before configuring GlobalProtect, verify that your environment satisfies the following operational requirements:<\/p>\n<ul>\n<li><strong>PAN-OS Version:<\/strong> PAN-OS 10.1 or higher installed on the firewall.<\/li>\n<li><strong>Licensing:<\/strong> A standard Palo Alto Networks firewall installation includes basic GlobalProtect features for Windows and macOS clients. Mobile device support (iOS, Android) and advanced checks (such as Host Information Profile\/HIP) require a GlobalProtect subscription license.<\/li>\n<li><strong>DNS Resolution:<\/strong> The portal FQDN (e.g., <code>gp.example.com<\/code>) must resolve publicly to the external interface address (<code>203.0.113.10<\/code>).<\/li>\n<li><strong>Routing:<\/strong> The firewall virtual router must have a valid default route out the external interface and internal routes back to local subnets.<\/li>\n<li><strong>Public Key Infrastructure (PKI):<\/strong> A valid Server Certificate signed by an enterprise internal Root CA or trusted third-party Public CA. Alternatively, a locally generated Root CA on PAN-OS can be used for lab testing.<\/li>\n<\/ul>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<p>Follow these steps to configure the SSL\/TLS profiles, network interfaces, authentication mechanisms, GlobalProtect Portal, GlobalProtect Gateway, and security policies.<\/p>\n<h3>Step 1: Certificate Management<\/h3>\n<p>GlobalProtect requires an SSL certificate for server authentication to prevent man-in-the-middle attacks when clients connect.<\/p>\n<ol>\n<li>Navigate to <strong>Device &gt; Certificate Management &gt; Certificates<\/strong>.<\/li>\n<li>If using a local lab Root CA, click <strong>Generate<\/strong>:\n<ul>\n<li><strong>Certificate Name:<\/strong> <code>Lab-Root-CA<\/code><\/li>\n<li><strong>Common Name:<\/strong> <code>Lab-Root-CA<\/code><\/li>\n<li>Check the box for <strong>Certificate Authority<\/strong>.<\/li>\n<li>Click <strong>Generate<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<li>Generate or import the Server Certificate for the portal\/gateway:\n<ul>\n<li>Click <strong>Generate<\/strong>.<\/li>\n<li><strong>Certificate Name:<\/strong> <code>GP-Server-Cert<\/code><\/li>\n<li><strong>Common Name:<\/strong> <code>gp.example.com<\/code> (or public IP <code>203.0.113.10<\/code>)<\/li>\n<li><strong>Signed By:<\/strong> Select <code>Lab-Root-CA<\/code> (or your internal CA).<\/li>\n<li>Add a Subject Alternative Name (SAN): Type <strong>DNS<\/strong>, Value <code>gp.example.com<\/code>.<\/li>\n<li>Click <strong>Generate<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h3>Step 2: Create an SSL\/TLS Service Profile<\/h3>\n<p>The SSL\/TLS profile defines the cryptographic parameters and certificates used by the portal and gateway endpoints.<\/p>\n<ol>\n<li>Navigate to <strong>Device &gt; Certificate Management &gt; SSL\/TLS Service Profile<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.<\/li>\n<li>Name the profile: <code>GP-SSL-Profile<\/code>.<\/li>\n<li>In the <strong>Certificate<\/strong> dropdown, select <code>GP-Server-Cert<\/code>.<\/li>\n<li>Set <strong>Min Version<\/strong> to <code>TLSv1.2<\/code> and <strong>Max Version<\/strong> to <code>Max<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 3: Configure Authentication<\/h3>\n<p>For this lab example, we will configure a local user database and link it to an Authentication Profile. Production enterprise environments typically link this profile to Active Directory via LDAP, RADIUS, or SAML (IdP).<\/p>\n<ol>\n<li>Navigate to <strong>Device &gt; Local User Database &gt; Users<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>. Define <code>vpnuser1<\/code>, assign a secure password, and click <strong>OK<\/strong>.<\/li>\n<li>Navigate to <strong>Device &gt; Authentication Profile<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.\n<ul>\n<li><strong>Name:<\/strong> <code>GP-Auth-Profile<\/code><\/li>\n<li><strong>Type:<\/strong> Select <code>Local Database<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Select the <strong>Advanced<\/strong> tab:\n<ul>\n<li>Under the Allow List, click <strong>Add<\/strong> and select <code>all<\/code> (or restrict to specific local user groups).<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 4: Create Tunnel Interface and Security Zone<\/h3>\n<p>GlobalProtect terminates client encrypted connections onto a logical Layer 3 tunnel interface.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; Zones<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.\n<ul>\n<li><strong>Name:<\/strong> <code>Remote-VPN<\/code><\/li>\n<li><strong>Log Type:<\/strong> <code>Layer3<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<li>Navigate to <strong>Network &gt; Interfaces &gt; Tunnel<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.\n<ul>\n<li><strong>Interface Name:<\/strong> <code>tunnel.1<\/code><\/li>\n<li><strong>Virtual Router:<\/strong> Select <code>default<\/code> (or your active virtual router).<\/li>\n<li><strong>Security Zone:<\/strong> Select <code>Remote-VPN<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>Leave the IPv4\/IPv6 address configuration blank (unassigned); the gateway dynamically handles IP allocations. Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 5: Configure the GlobalProtect Gateway<\/h3>\n<p>The gateway authenticates the client, assigns internal network configurations (IP address, DNS servers), establishes the encrypted tunnel, and controls split-tunnel routes.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; GlobalProtect &gt; Gateways<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.<\/li>\n<li>In the <strong>General<\/strong> tab:\n<ul>\n<li><strong>Name:<\/strong> <code>GP-Gateway<\/code><\/li>\n<li><strong>Interface:<\/strong> Select <code>ethernet1\/1<\/code> (external interface).<\/li>\n<li><strong>Address Type:<\/strong> <code>IPv4<\/code><\/li>\n<li><strong>IPv4 Address:<\/strong> Select <code>203.0.113.10\/24<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>In the <strong>Authentication<\/strong> tab:\n<ul>\n<li><strong>SSL\/TLS Service Profile:<\/strong> Select <code>GP-SSL-Profile<\/code>.<\/li>\n<li>Under Client Authentication, click <strong>Add<\/strong>:\n<ul>\n<li><strong>Name:<\/strong> <code>Gateway-Auth<\/code><\/li>\n<li><strong>Authentication Profile:<\/strong> Select <code>GP-Auth-Profile<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>In the <strong>Agent<\/strong> tab:\n<ul>\n<li>Select <strong>Tunnel Settings<\/strong>:\n<ul>\n<li>Check <strong>Tunnel Mode<\/strong>.<\/li>\n<li><strong>Tunnel Interface:<\/strong> Select <code>tunnel.1<\/code>.<\/li>\n<li>Check <strong>Enable IPsec<\/strong> (allows high-performance ESP encapsulation with automatic SSL fallback).<\/li>\n<\/ul>\n<\/li>\n<li>Select <strong>Client Configuration<\/strong> and click <strong>Add<\/strong>:\n<ul>\n<li><strong>Name:<\/strong> <code>Gateway-Client-Config<\/code><\/li>\n<li><strong>Authentication Profile:<\/strong> Select <code>GP-Auth-Profile<\/code>.<\/li>\n<li>Navigate to the <strong>IP Pools<\/strong> sub-tab: Click <strong>Add<\/strong> and enter the IP pool range: <code>10.200.1.10-10.200.1.250<\/code>.<\/li>\n<li>Navigate to the <strong>Split Tunnel<\/strong> sub-tab: Under <strong>Include<\/strong>, click <strong>Add<\/strong> and specify the internal destination route: <code>10.10.0.0\/16<\/code>.<\/li>\n<li>Navigate to the <strong>DNS<\/strong> sub-tab: Enter internal enterprise DNS servers if applicable (e.g., <code>10.10.1.53<\/code>).<\/li>\n<li>Click <strong>OK<\/strong> to close the Client Configuration window.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong> to save the Gateway configuration.<\/li>\n<\/ol>\n<h3>Step 6: Configure the GlobalProtect Portal<\/h3>\n<p>The portal serves as the single management endpoint for remote clients. It handles initial client authentication, provides agent software downloads, and delivers gateway connection configurations.<\/p>\n<ol>\n<li>Navigate to <strong>Network &gt; GlobalProtect &gt; Portals<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.<\/li>\n<li>In the <strong>General<\/strong> tab:\n<ul>\n<li><strong>Name:<\/strong> <code>GP-Portal<\/code><\/li>\n<li><strong>Interface:<\/strong> Select <code>ethernet1\/1<\/code>.<\/li>\n<li><strong>Address Type:<\/strong> <code>IPv4<\/code><\/li>\n<li><strong>IPv4 Address:<\/strong> Select <code>203.0.113.10\/24<\/code>.<\/li>\n<\/ul>\n<\/li>\n<li>In the <strong>Authentication<\/strong> tab:\n<ul>\n<li><strong>SSL\/TLS Service Profile:<\/strong> Select <code>GP-SSL-Profile<\/code>.<\/li>\n<li>Under Client Authentication, click <strong>Add<\/strong>:\n<ul>\n<li><strong>Name:<\/strong> <code>Portal-Auth<\/code><\/li>\n<li><strong>Authentication Profile:<\/strong> Select <code>GP-Auth-Profile<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>In the <strong>Agent<\/strong> tab:\n<ul>\n<li>Click <strong>Add<\/strong> to create an Agent Configuration:\n<ul>\n<li><strong>Name:<\/strong> <code>Portal-Agent-Config<\/code><\/li>\n<li><strong>Authentication Profile:<\/strong> Select <code>GP-Auth-Profile<\/code>.<\/li>\n<li>Navigate to the <strong>External<\/strong> sub-tab under <strong>Gateways<\/strong>:\n<ul>\n<li>Click <strong>Add<\/strong> under External Gateways:\n<ul>\n<li><strong>Name:<\/strong> <code>External-GW<\/code><\/li>\n<li><strong>Address:<\/strong> Enter the FQDN <code>gp.example.com<\/code> or IP <code>203.0.113.10<\/code>.<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>Navigate to the <strong>App<\/strong> sub-tab: Set client connection rules (e.g., <strong>Connect Method:<\/strong> <code>User-Auth<\/code>).<\/li>\n<li>Click <strong>OK<\/strong> to close the Agent Configuration window.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong> to save the Portal configuration.<\/li>\n<\/ol>\n<h3>Step 7: Configure Security Rules<\/h3>\n<p>Traffic emerging from the <code>tunnel.1<\/code> interface resides within the <code>Remote-VPN<\/code> security zone. You must add security rules to permit traffic from this zone to internal networks.<\/p>\n<ol>\n<li>Navigate to <strong>Policies &gt; Security<\/strong>.<\/li>\n<li>Click <strong>Add<\/strong>.\n<ul>\n<li><strong>Name:<\/strong> <code>Allow-GP-VPN-to-Internal<\/code><\/li>\n<li><strong>Source Tab:<\/strong> Source Zone select <code>Remote-VPN<\/code>. Source Address select <code>Any<\/code> (or <code>10.200.1.0\/24<\/code>).<\/li>\n<li><strong>Destination Tab:<\/strong> Destination Zone select <code>Trust<\/code>. Destination Address select <code>10.10.0.0\/16<\/code>.<\/li>\n<li><strong>Application Tab:<\/strong> Select desired application objects (e.g., <code>web-browsing<\/code>, <code>ssl<\/code>, <code>ssh<\/code>) or leave as <code>any<\/code> for testing.<\/li>\n<li><strong>Action Tab:<\/strong> Select <code>Allow<\/code>. Enable logging at session end.<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<div style=\"background-color: #fff3cd;border-left: 4px solid #ffc107;padding: 12px;margin: 16px 0\">\n    <strong>CAUTION:<\/strong> Committing configuration changes applies modifications directly to the running configuration. If you are modifying interface bindings or security policies in production environments, ensure you perform changes during an approved change window.\n<\/div>\n<ol start=\"4\">\n<li>Click <strong>Commit<\/strong> in the upper right corner of the GUI to process and finalize your candidate configuration.<\/li>\n<\/ol>\n<h2>CLI Section<\/h2>\n<p>The PAN-OS Command Line Interface (CLI) allows you to inspect operational statuses, evaluate authentication mechanisms, and verify tunnel parameters quickly.<\/p>\n<p>To test client authentication against a configured Authentication Profile via the CLI, use the following operational command:<\/p>\n<pre><code>test authentication profile GP-Auth-Profile username vpnuser1 password<\/code><\/pre>\n<div style=\"background-color: #fff3cd;border-left: 4px solid #ffc107;padding: 12px;margin: 16px 0\">\n    <strong>CAUTION:<\/strong> Running authentication tests directly from the CLI will process credentials against the target authentication server or local database. Ensure plain-text credentials are not exposed in session transcripts or shared terminal windows.\n<\/div>\n<p>To verify that the designated tunnel interface is operational and attached to the virtual router:<\/p>\n<pre><code>show interface tunnel.1<\/code><\/pre>\n<p>To view active connections established on the GlobalProtect Gateway:<\/p>\n<pre><code>show global-protect-gateway current-connection gateway GP-Gateway<\/code><\/pre>\n<p>To inspect runtime statistics for the GlobalProtect Portal:<\/p>\n<pre><code>show global-protect-portal statistics<\/code><\/pre>\n<p>To inspect the routing engine table for dynamic routes instantiated by active client connections:<\/p>\n<pre><code>show routing route virtual-router default<\/code><\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding the distinct stages of control-plane signaling and data-plane routing clarifies how GlobalProtect processes packet flows.<\/p>\n<ol>\n<li><strong>Portal Authentication (Control Plane):<\/strong>\n<ul>\n<li>The client GlobalProtect App initiates an HTTPS request (TCP port 443) to <code>gp.example.com<\/code> (<code>203.0.113.10<\/code>).<\/li>\n<li>The firewall validates the server certificate, authenticates the user via <code>GP-Auth-Profile<\/code>, and sends the client configuration payload XML.<\/li>\n<li>The XML response contains the list of available external gateways, client app behaviors, and trust configurations.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Gateway Tunnel Establishment (Control\/Data Plane):<\/strong>\n<ul>\n<li>The client initiates an authentication request to the external gateway address (<code>203.0.113.10<\/code>).<\/li>\n<li>Upon successful authentication, the gateway assigns a virtual client IP address (e.g., <code>10.200.1.10<\/code>) from the configured IP pool.<\/li>\n<li>The gateway attempts to form an IPsec tunnel using ESP (UDP port 4500). If firewall middleboxes block IPsec transport, the client seamlessly falls back to SSL encapsulation over TCP port 443.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Data Forwarding &amp; Policy Enforcement (Data Plane):<\/strong>\n<ul>\n<li>The client OS installs a dynamic network interface and injects routes based on the split-tunnel profile (e.g., route <code>10.10.0.0\/16<\/code> into the virtual adapter).<\/li>\n<li>When the user accesses an internal application (e.g., <code>10.10.5.20<\/code>), packets are encapsulated into the IPsec\/SSL tunnel.<\/li>\n<li>Encapsulated packets arrive at <code>ethernet1\/1<\/code> (zone <code>Untrust<\/code>). The firewall decapsulates the packets and logically attributes the unencapsulated traffic to interface <code>tunnel.1<\/code> and zone <code>Remote-VPN<\/code>.<\/li>\n<li>The firewall evaluates Security Policies:\n<ul>\n<li><strong>Source Zone:<\/strong> <code>Remote-VPN<\/code><\/li>\n<li><strong>Source IP:<\/strong> <code>10.200.1.10<\/code><\/li>\n<li><strong>Destination Zone:<\/strong> <code>Trust<\/code><\/li>\n<li><strong>Destination IP:<\/strong> <code>10.10.5.20<\/code><\/li>\n<\/ul>\n<\/li>\n<li>If permitted, the packet routes out physical interface <code>ethernet1\/2<\/code> to the internal network destination.<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>To verify operational status across both the firewall and client endpoints, run the following diagnostic checks:<\/p>\n<h3>1. Client App Verification<\/h3>\n<p>Open the GlobalProtect Agent on the remote client machine. Verify that the client displays <strong>Connected<\/strong>. Click the menu icon and inspect the <strong>Connection Details<\/strong> tab. Confirm that:<\/p>\n<ul>\n<li>The assigned IP address matches an entry from the configured pool (e.g., <code>10.200.1.10<\/code>).<\/li>\n<li>The assigned gateway is <code>gp.example.com<\/code>.<\/li>\n<li>The connection type lists <code>IPsec<\/code> (or <code>SSL<\/code>).<\/li>\n<\/ul>\n<h3>2. GUI Gateway Active Users Check<\/h3>\n<p>Navigate to <strong>Network &gt; GlobalProtect &gt; Gateways<\/strong>. Click the <strong>Remote Users<\/strong> link on the <code>GP-Gateway<\/code> row. Confirm that <code>vpnuser1<\/code> is displayed with their assigned virtual IP, tunnel status, client OS type, and public IP address.<\/p>\n<h3>3. Traffic Log Verification<\/h3>\n<p>Navigate to <strong>Monitor &gt; Logs &gt; Traffic<\/strong>. Filter logs using the following query structure:<\/p>\n<pre><code>( zone.src eq Remote-VPN ) and ( zone.dst eq Trust )<\/code><\/pre>\n<p>Confirm that traffic sourced from the client virtual IP (<code>10.200.1.10<\/code>) to internal applications shows an action of <code>allow<\/code> and correctly maps to the <code>Allow-GP-VPN-to-Internal<\/code> rule.<\/p>\n<h2>Troubleshooting<\/h2>\n<p>When remote access connections fail, isolate the issue using systematic verification of symptoms, underlying root causes, and CLI inspection commands.<\/p>\n<h3>Symptom 1: Portal Connection Fails with Certificate Error<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> The client machine does not trust the Root CA that signed the portal server certificate, or the certificate Subject Alternative Name (SAN) does not match the FQDN entered by the user.<\/li>\n<li><strong>Verification Check:<\/strong> Access the portal FQDN using a standard web browser on the client machine (<code>https:\/\/gp.example.com<\/code>). Inspect certificate trust errors. Import the Root CA certificate into the client machine&#8217;s Trusted Root Certification Authorities store.<\/li>\n<\/ul>\n<h3>Symptom 2: GlobalProtect Connects, but Internal Application Traffic Times Out<\/h3>\n<ul>\n<li><strong>Likely Cause 1: Missing Return Route.<\/strong> Internal routers or downstream firewalls do not possess a route directing the VPN client pool network (<code>10.200.1.0\/24<\/code>) back to the Palo Alto firewall&#8217;s internal interface (<code>10.10.1.1<\/code>).<\/li>\n<li><strong>Likely Cause 2: Security Policy Enforcement.<\/strong> No security policy rule exists permitting traffic from the <code>Remote-VPN<\/code> zone to the destination zone.<\/li>\n<li><strong>Verification Check:<\/strong> Inspect traffic logs under <strong>Monitor &gt; Logs &gt; Traffic<\/strong>. If logs show traffic with <code>Action: drop<\/code> or `Reset`, check security policy definitions. If logs show <code>bytes_sent<\/code> but zero <code>bytes_received<\/code>, inspect internal routing for missing return paths to <code>10.200.1.0\/24<\/code>.<\/li>\n<\/ul>\n<h3>Symptom 3: Tunnel Connects via SSL Instead of IPsec<\/h3>\n<ul>\n<li><strong>Likely Cause:<\/strong> Intermediate networks or ISP firewalls are dropping UDP port 4500 (IPsec NAT-Traversal) or ESP traffic.<\/li>\n<li><strong>Verification Check:<\/strong> Run the CLI operational command:\n<pre><code>show global-protect-gateway current-connection gateway GP-Gateway<\/code><\/pre>\n<p>        Examine the tunnel protocol listing. If SSL is shown, confirm that upstream edge firewalls permit UDP port 4500 inbound to the public firewall interface.\n    <\/li>\n<\/ul>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Unassigned Tunnel Interface Zone:<\/strong> Creating <code>tunnel.1<\/code> but failing to assign it to a Layer 3 Security Zone (e.g., <code>Remote-VPN<\/code>). Unassigned tunnel interfaces drop incoming traffic automatically.<\/li>\n<li><strong>Unassigned Virtual Router:<\/strong> Creating the tunnel interface without placing it inside an active Virtual Router prevents the firewall from populating routing entries.<\/li>\n<li><strong>Certificate Mismatch:<\/strong> Using an IP address inside the certificate&#8217;s Common Name when clients initiate connections using a Domain Name (FQDN), leading to client validation failures.<\/li>\n<li><strong>Missing Split-Tunnel Route Configuration:<\/strong> Omitting required corporate subnets from the Gateway Split-Tunnel Include list, causing client devices to bypass the VPN tunnel for corporate resources.<\/li>\n<li><strong>Overlapping IP Pools:<\/strong> Assigning a GlobalProtect Client IP Pool range that overlaps with existing physical internal networks or client local LAN subnets (e.g., using <code>192.168.1.0\/24<\/code>).<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>Before moving a GlobalProtect configuration into production, incorporate these enterprise standards:<\/p>\n<ul>\n<li><strong>Multi-Factor Authentication (MFA):<\/strong> Integrate your Authentication Profile with SAML 2.0 Identity Providers (such as Okta, Azure AD, or Ping Identity) or RADIUS with MFA to enforce second-factor authentication for remote users.<\/li>\n<li><strong>Redundant External Gateways:<\/strong> Deploy multiple active GlobalProtect gateways across geographically dispersed firewalls. Configure priority-based gateway lists inside the portal agent configuration for automatic failover and load distribution.<\/li>\n<li><strong>Host Information Profile (HIP):<\/strong> Require GlobalProtect subscription licenses to enforce device posture checks (e.g., checking for active disk encryption, mandatory endpoint protection, and patch management) prior to granting network access.<\/li>\n<li><strong>Bandwidth and Capacity Planning:<\/strong> Monitor firewall dataplane CPU usage, session table limits, and SSL decryption load when sizing GlobalProtect deployments for large remote workforces.<\/li>\n<\/ul>\n<h2>Related NetworkFix Guides<\/h2>\n<ul>\n<li><a href=\"\/en\/tutorials\/palo\/palo-alto-ipsec-vpn-troubleshooting\/\">Palo Alto IPsec VPN troubleshooting<\/a><\/li>\n<li><a href=\"\/en\/tutorials\/palo\/how-to-generate-a-palo-alto-certificate-signed-by-microsoft-ad-cs\/\">Generate a Palo Alto certificate signed by Microsoft AD CS<\/a><\/li>\n<li><a href=\"\/en\/tutorials\/palo\/palo-alto-log-forwarding-syslog-siem\/\">Palo Alto log forwarding to Syslog or SIEM<\/a><\/li>\n<li><a href=\"\/en\/tutorials\/palo\/palo-alto-security-policy-configuration\/\">Palo Alto security policy configuration<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Implementing a robust <strong>Palo Alto GlobalProtect configuration<\/strong> provides secure, policy-driven remote access for remote workers. By configuring server certificates, logical tunnel interfaces, dedicated security zones, split-tunnel rules, and authentication profiles, security teams gain complete visibility and control over off-site devices accessing internal enterprise application environments.<\/p>","protected":false},"excerpt":{"rendered":"<p>Configure a Palo Alto GlobalProtect remote-user deployment with authentication, tunnel verification and practical troubleshooting checks.<\/p>","protected":false},"author":2,"featured_media":1520,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[5],"tags":[29,75,73,1183,32,31],"class_list":["post-1521","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-palo","tag-firewall-tutorial","tag-globalprotect","tag-intermediate","tag-palo-alto-globalprotect-configuration","tag-palo-alto-networks","tag-pan-os"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Palo Alto GlobalProtect Remote User Configuration Guide<\/title>\n<meta name=\"description\" content=\"Set up Palo Alto GlobalProtect for a remote user with authentication, certificates, tunnel verification, security policies and troubleshooting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-globalprotect-configuration\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Palo Alto GlobalProtect Configuration with a Remote User Example\" \/>\n<meta property=\"og:description\" content=\"Set up Palo Alto GlobalProtect for a remote user with authentication, certificates, tunnel verification, security policies and troubleshooting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-globalprotect-configuration\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-13T09:41:44+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-30T09:27:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"Palo Alto GlobalProtect Configuration with a Remote User Example\",\"datePublished\":\"2026-09-13T09:41:44+00:00\",\"dateModified\":\"2026-09-30T09:27:50+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/\"},\"wordCount\":2309,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg\",\"keywords\":[\"Firewall Tutorial\",\"GlobalProtect\",\"Intermediate\",\"Palo Alto GlobalProtect configuration\",\"Palo Alto Networks\",\"PAN-OS\"],\"articleSection\":[\"Palo Alto\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/\",\"name\":\"Palo Alto GlobalProtect Remote User Configuration Guide\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg\",\"datePublished\":\"2026-09-13T09:41:44+00:00\",\"dateModified\":\"2026-09-30T09:27:50+00:00\",\"description\":\"Set up Palo Alto GlobalProtect for a remote user with authentication, certificates, tunnel verification, security policies and troubleshooting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg\",\"width\":1200,\"height\":630,\"caption\":\"Palo Alto GlobalProtect Configuration with a Remote User Example\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/palo\\\/palo-alto-globalprotect-configuration\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Palo Alto GlobalProtect Configuration with a Remote User Example\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Palo Alto GlobalProtect Remote User Configuration Guide","description":"Set up Palo Alto GlobalProtect for a remote user with authentication, certificates, tunnel verification, security policies and troubleshooting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-globalprotect-configuration\/","og_locale":"en_US","og_type":"article","og_title":"Palo Alto GlobalProtect Configuration with a Remote User Example","og_description":"Set up Palo Alto GlobalProtect for a remote user with authentication, certificates, tunnel verification, security policies and troubleshooting.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/palo\/palo-alto-globalprotect-configuration\/","og_site_name":"NetworkFix","article_published_time":"2026-09-13T09:41:44+00:00","article_modified_time":"2026-09-30T09:27:50+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg","type":"image\/jpeg"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"Palo Alto GlobalProtect Configuration with a Remote User Example","datePublished":"2026-09-13T09:41:44+00:00","dateModified":"2026-09-30T09:27:50+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/"},"wordCount":2309,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg","keywords":["Firewall Tutorial","GlobalProtect","Intermediate","Palo Alto GlobalProtect configuration","Palo Alto Networks","PAN-OS"],"articleSection":["Palo Alto"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/","url":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/","name":"Palo Alto GlobalProtect Remote User Configuration Guide","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg","datePublished":"2026-09-13T09:41:44+00:00","dateModified":"2026-09-30T09:27:50+00:00","description":"Set up Palo Alto GlobalProtect for a remote user with authentication, certificates, tunnel verification, security policies and troubleshooting.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/palo-alto-globalprotect-configuration-with-a-remote-user-example-featured.jpg","width":1200,"height":630,"caption":"Palo Alto GlobalProtect Configuration with a Remote User Example"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/palo\/palo-alto-globalprotect-configuration\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"Palo Alto GlobalProtect Configuration with a Remote User Example"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1521","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=1521"}],"version-history":[{"count":3,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1521\/revisions"}],"predecessor-version":[{"id":1639,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1521\/revisions\/1639"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/1520"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=1521"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=1521"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=1521"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}