Vigyata.AI
Is this your channel?

#paloaltofirewalltraining | Day 47 | How to Configure Global Protect Portal and Gateway

464 views· 13 likes· 22:55· Feb 6, 2026

🛍️ Products Mentioned (2)

Join this channel to get access to perks: https://www.youtube.com/channel/UCBujQdd5rBRg7n70vy7YmAQ/join Please checkout my new video on How to Configure Global Protect VPN with AD Authentication. If you like this video give it a thumps up and subscribe my channel for more video. Have any question put it on comment section Recommend Video #paloaltofirewalltraining | Day 44 | How to Configure Global Protect VPN in Palo Alto https://youtu.be/8imTv9xYlJY #paloaltofirewalltraining | Day 43 | Global Protect SSL VPN in Palo Alto | Concept https://youtu.be/0ca7xsa1K_w Recommend Link (Playlist for EVE-NG LAB Setup) https://www.youtube.com/playlist?list=PLaUiizP3D7fPMmUQqS5QKX_FVSoMP68Z5 Palo Alto Certification information URL: https://www.paloaltonetworks.com/services/education For Palo Alto Documentation https://docs.paloaltonetworks.com/ Please follow me Instagram : https://www.instagram.com/bikashtech Twitter : https://twitter.com/Bikashshaw82 E-mail ID : bikashshaw261@gmail.com #Paloaltotraining ##bikashtech #paloaltofirewalltraining #paloaltonetworks #paloaltotraining #paloaltovpn #vpn #ike #ipsec

About This Video

In Day 47 of my PCNSA series, I show you a real-world style GlobalProtect setup where the Portal and the Gateway are on different Palo Alto firewalls. In my earlier videos I configured portal and gateway on the same device, but in industry you will often see them separated. Here the client first connects to the Portal, and the Portal redirects the client to the correct Gateway. After that, the client initiates the GlobalProtect (IPSec) VPN tunnel with the Gateway and all further inside access goes through the Gateway. In the lab, I keep the topology simple so you focus on the concept and traffic flow. I configure the Portal interface (outside) with DHCP, generate a certificate for the Portal (I use IP address because I don’t have FQDN), create a local user and authentication profile, and build the Portal config including the external gateway IP mapping. Then on the Gateway side I align the authentication to local database as well. Finally, from the client I connect using the Portal IP, install the certificate to trusted to avoid warnings, authenticate with my test user, and verify that the actual connected gateway IP is different from the portal. I also quickly validate the flow using packet capture/streams to show portal-first, gateway-next behavior—very useful for troubleshooting mindset.

Frequently Asked Questions

🎬 More from Bikash's Tech