{"id":215,"date":"2022-04-25T07:32:46","date_gmt":"2022-04-25T11:32:46","guid":{"rendered":"https:\/\/opentextbc.ca\/paloalto\/chapter\/remote-access-vpn\/"},"modified":"2023-11-28T19:05:21","modified_gmt":"2023-11-29T00:05:21","slug":"remote-access-vpn","status":"publish","type":"chapter","link":"https:\/\/opentextbc.ca\/paloalto\/chapter\/remote-access-vpn\/","title":{"raw":"3.2 Remote Access VPN","rendered":"3.2 Remote Access VPN"},"content":{"raw":"<div class=\"textbox textbox--learning-objectives\"><header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n \t<li>Configure a tunnel interface<\/li>\n \t<li>Configure a remote access VPN<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox\">\n\n<strong>Prerequisites<\/strong>:\n<ul>\n \t<li>Setup Zones<\/li>\n \t<li>Some interface configuration<\/li>\n \t<li>Create a new user<\/li>\n \t<li>Create an auth policy<\/li>\n \t<li>Policy that allows VPN to Inside<\/li>\n \t<li>Policy that allows Outside to VPN<\/li>\n \t<li>Knowledge of previous labs<\/li>\n<\/ul>\n<\/div>\n<div class=\"textbox shaded\">\n\n<strong>Scenario<\/strong>: VPNs aren't just about changing your location like many advertisements say they're for. What it's really used for is to securely access a remote location's resources like your workplace, or even your own home. That is what this lab will focus on. We are going to install GlobalProtect Agent on Kali and then we'll try to reach the Internal through VPN connection.\n\n<\/div>\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"990\"]<img class=\"wp-image-188 size-full\" style=\"text-align: initial; font-size: 14pt;\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image.png\" alt=\"main scenario\" width=\"990\" height=\"544\"> Figure 3.27: Main scenario[\/caption]\n<table class=\"grid\" style=\"border-collapse: collapse; width: 100%; height: 75px;\" border=\"0\"><caption>Table 3.5: Addressing Table<\/caption>\n<tbody>\n<tr style=\"height: 15px;\">\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Device<\/th>\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">PaloAlto-1<\/td>\n<td style=\"width: 50%; height: 15px;\">management: 192.168.0.1\/24\nEthernet1\/1: 10.0.0.1\/24\nEthernet1\/2: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Internal (WordPress)<\/td>\n<td style=\"width: 50%; height: 15px;\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">KaliLinux2019.3-1<\/td>\n<td style=\"width: 50%; height: 15px;\">eth0: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Management<\/td>\n<td style=\"width: 50%; height: 15px;\">eth0: 192.168.0.2\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse; width: 100%; height: 60px;\" border=\"0\"><caption>Table 3.6: Zone Configuration<\/caption>\n<tbody>\n<tr style=\"height: 15px;\">\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Zone<\/th>\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Interface<\/th>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Inside<\/td>\n<td style=\"width: 50%; height: 15px;\">Ethernet1\/1<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Outside<\/td>\n<td style=\"width: 50%; height: 15px;\">Ethernet1\/2<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">VPN<\/td>\n<td style=\"width: 50%; height: 15px;\">Tunnel.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 style=\"page-break-before: always;\">Create a Tunnel Interface<\/h2>\nUnder <strong>Network &gt; Interfaces<\/strong> in the Tunnel tab, click <b>Add<\/b>.\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-189 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1.jpg\" alt=\"Creating a Tunnel\" width=\"1026\" height=\"830\"> Figure 3.28: Creating a Tunnel[\/caption]\n<p style=\"page-break-before: always;\">In the new window, change the virtual router to default, and the security zone to the VPN zone.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-190 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2.jpg\" alt=\"Tunnel Interface\" width=\"1026\" height=\"830\"> Figure 3.29: Tunnel Interface[\/caption]\n\nThen click <b>OK<\/b>.\n<h2 style=\"page-break-before: always;\">Enable User ACL for a Zone<\/h2>\nUnder <strong>Network &gt; Zone<\/strong>, click the VPN zone.\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-191 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3.jpg\" alt=\"Create a VPN Zone\" width=\"1026\" height=\"830\"> Figure 3.30: Create a VPN Zone[\/caption]\n<p style=\"page-break-before: always;\">Tick the <strong>Enable user identification<\/strong> box.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-192 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4.jpg\" alt=\"Enable User Identification under VPN Zone\" width=\"1026\" height=\"830\"> Figure 3.31: Enable User Identification under VPN Zone[\/caption]\n\nThen press <strong>OK<\/strong>.\n<h2 style=\"page-break-before: always;\">Generate Certs<\/h2>\nUnder <strong>Device &gt; Certificate Management &gt; Certificates<\/strong>, click\u00a0on <b>Generate.<\/b>\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-193 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5.jpg\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\"> Figure 3.32: Generate a certificate[\/caption]\n\nConfigure these settings in the new window:\n<table class=\"grid\" style=\"border-collapse: collapse; width: 100%; height: 60px;\" border=\"0\"><caption>Table 3.7: Certificate Generation<\/caption>\n<tbody>\n<tr style=\"height: 15px;\">\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Certificate Name<\/td>\n<td style=\"width: 50%; height: 15px;\"><em>Cert Name Here<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Common Name<\/td>\n<td style=\"width: 50%; height: 15px;\"><em>The DHCP IP of Ethernet1\/2<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Certificate Authority<\/td>\n<td style=\"width: 50%; height: 15px;\"><em>Tick this box<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-194 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image.png\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\"> Figure 3.33: Generate a certificate[\/caption]\n\nThen click <strong>Generate<\/strong>.\n<h2 style=\"page-break-before: always;\">Create an SSL\/TLS Service Profile<\/h2>\nUnder <strong>Device &gt; Certificate Management &gt; SSL\/TLS<\/strong> Service Profile, click <b>Add<\/b>.\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-195 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6.jpg\" alt=\"Add SSL\/TLS Service Profile\" width=\"1026\" height=\"830\"> Figure 3.34: Add SSL\/TLS Service Profile[\/caption]\n<p style=\"page-break-before: always;\">In the new window, add the certificate you generated.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-196 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image.png\" alt=\"Configure SSL\/TLS Service Profile\" width=\"1026\" height=\"830\"> Figure 3.35: Configure SSL\/TLS Service Profile[\/caption]\n\nThen click <b>OK<\/b>.\n<h2 style=\"page-break-before: always;\">Create a GlobalProtect Portal<\/h2>\nUnder <strong>Network &gt; GlobalProtect &gt; Portals<\/strong>, then click <b>Add<\/b>.\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-197 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7.jpg\" alt=\"Add a Portal\" width=\"1026\" height=\"830\"> Figure 3.36: Add a Portal[\/caption]\n<p style=\"page-break-before: always;\">In the general tab, set the interface to Ethernet1\/2.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-198 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8.jpg\" alt=\"GlobalProtect Portal Configuration\" width=\"1026\" height=\"830\"> Figure 3.37: GlobalProtect Portal Configuration[\/caption]\n<p style=\"page-break-before: always;\">In the authentication tab, select SSL\/TLS profile you created in the previous step, then click <strong>Add<\/strong>.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-199 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9.jpg\" alt=\"Adding SSL\/TLS Profile\" width=\"1026\" height=\"830\"> Figure 3.38: Adding SSL\/TLS Profile[\/caption]\n<p style=\"page-break-before: always;\">In the new window, change the authentication profile, then press <strong>OK<\/strong>.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-200 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10.jpg\" alt=\"Adding Authentication Profile\" width=\"1026\" height=\"830\"> Figure 3.39: Adding Authentication Profile[\/caption]\n<p style=\"page-break-before: always;\">In the agent tab, in the agent section, click <b>Add<\/b>.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-201 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11.jpg\" alt=\"Adding the agent\" width=\"1026\" height=\"830\"> Figure 3.40: Adding the agent[\/caption]\n<p style=\"page-break-before: always;\">In the internal tab in the Internal gateway, click <b>Add.<\/b><\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-202 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12.jpg\" alt=\"Configure Internal Gateway\" width=\"1026\" height=\"830\"> Figure 3.41: Configure Internal Gateway[\/caption]\n<p style=\"page-break-before: always;\">In this window, change the Address to select IP, and in the IPv4 box, type in the IP of Ethernet1\/2.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-203 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a.jpg\" alt=\"Set the IP address for Internal Gateway\" width=\"1026\" height=\"830\"> Figure 3.42: Set the IP address for Internal Gateway[\/caption]\n<p style=\"page-break-before: always;\">Press <b>OK<\/b> twice to get back to the agent tab. Then in the trusted root ca section, add your generated cert, and tick the box to install in local root certificate store.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-204 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image.png\" alt=\"Add the Root CA certificate\" width=\"1026\" height=\"830\"> Figure 3.43: Add the Root CA certificate[\/caption]\n\nThen press <b>OK<\/b>.\n<h2 style=\"page-break-before: always;\">Create a GlobalProtect Gateway<\/h2>\nUnder <strong>Network &gt; GlobalProtect &gt; Gateways<\/strong>, click <b>Add<\/b>.\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-205 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14.jpg\" alt=\"Add a Gateway\" width=\"1026\" height=\"830\"> Figure 3.44: Add a Gateway[\/caption]\n<p style=\"page-break-before: always;\">In the general tab, set the interface to Ethernet1\/2.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-206 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image.png\" alt=\"GlobalProtect Gateway Configuration\" width=\"1026\" height=\"830\"> Figure 3.45: GlobalProtect Gateway Configuration[\/caption]\n<p style=\"page-break-before: always;\">In the Authentication tab, add your <strong>SSL\/TLS<\/strong> profile, then click <b>Add<\/b>.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-207 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15.jpg\" alt=\"SSL\/TLS Service Profile\" width=\"1026\" height=\"830\"> Figure 3.46: SSL\/TLS Service Profile[\/caption]\n<p style=\"page-break-before: always;\">In the new window, select your authentication profile, then click <b>OK.<\/b><\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-208 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16.jpg\" alt=\"Authentication Profile\" width=\"1026\" height=\"830\"> Figure 3.47: Authentication Profile[\/caption]\n<p style=\"page-break-before: always;\">Under the agent tab, in tunnel settings, tick the tunnel mode checkbox and select the tunnel you made.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-209 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17.jpg\" alt=\"Tunnel Mode and Interface\" width=\"1026\" height=\"830\"> Figure 3.48: Tunnel Mode and Interface[\/caption]\n<p style=\"page-break-before: always;\">In client settings, click <b>Add<\/b>.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-210 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18.jpg\" alt=\"Client Settings\" width=\"1026\" height=\"830\"> Figure 3.49: Client Settings[\/caption]\n<p style=\"page-break-before: always;\">Make sure the <strong>Any<\/strong> checkbox is ticked on top of the OS category, then press <b>OK<\/b>.<\/p>\n\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-211 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19.jpg\" alt=\"Select Client as Any\" width=\"1026\" height=\"830\"> Figure 3.50: Select Client as Any[\/caption]\n<p style=\"page-break-before: always;\">In client IP pool settings, add an IP pool range of this:<\/p>\n<span style=\"background-color: #d1d1d1;\"><code>172.16.10.1-172.16.10.10<\/code><\/span>\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-212 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20.jpg\" alt=\"IP Pool Configuration\" width=\"1026\" height=\"830\"> Figure 3.51: IP Pool Configuration[\/caption]\n\nThen press <b>OK<\/b>. Don't forget to commit the configuration!\n<h2 style=\"page-break-before: always;\">Install the GlobalProtect Client on Kali<\/h2>\nOpen up a terminal window and run the following commands:\n<div class=\"textbox shaded\"><code>#curl -L https:\/\/bit.ly\/32Ljx1y --output GP.deb<\/code>\n<code>#sudo dpkg -i GP.deb<\/code>\n<code>#globalprotect connect -p [IP of Palo Alto Ethernet1\/2 Here]<\/code><\/div>\nWhen connecting, it will show an error about validation. Type in y then press enter.\n\nIt will also ask for your username and password. Enter the one you created prior.\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-213 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image.png\" alt=\"Installing GlobalProtect on Kali Linux\" width=\"1026\" height=\"830\"> Figure 3.52: Installing GlobalProtect on Kali Linux[\/caption]\n<h2 style=\"page-break-before: always;\">Test Remote Access VPN<\/h2>\nOn Kali, after connecting to GlobalProtect, navigate to the IP of the WordPress Server (Internal).\n\n[caption id=\"attachment_214\" align=\"aligncenter\" width=\"1026\"]<img class=\"wp-image-214 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\"> Figure 3.53: Verify your configuration[\/caption]\n\nIf everything was correct, it should display the WordPress site!","rendered":"<div class=\"textbox textbox--learning-objectives\">\n<header class=\"textbox__header\">\n<p class=\"textbox__title\">Learning Objectives<\/p>\n<\/header>\n<div class=\"textbox__content\">\n<ul>\n<li>Configure a tunnel interface<\/li>\n<li>Configure a remote access VPN<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<div class=\"textbox\">\n<p><strong>Prerequisites<\/strong>:<\/p>\n<ul>\n<li>Setup Zones<\/li>\n<li>Some interface configuration<\/li>\n<li>Create a new user<\/li>\n<li>Create an auth policy<\/li>\n<li>Policy that allows VPN to Inside<\/li>\n<li>Policy that allows Outside to VPN<\/li>\n<li>Knowledge of previous labs<\/li>\n<\/ul>\n<\/div>\n<div class=\"textbox shaded\">\n<p><strong>Scenario<\/strong>: VPNs aren&#8217;t just about changing your location like many advertisements say they&#8217;re for. What it&#8217;s really used for is to securely access a remote location&#8217;s resources like your workplace, or even your own home. That is what this lab will focus on. We are going to install GlobalProtect Agent on Kali and then we&#8217;ll try to reach the Internal through VPN connection.<\/p>\n<\/div>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 990px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-188 size-full\" style=\"text-align: initial; font-size: 14pt;\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image.png\" alt=\"main scenario\" width=\"990\" height=\"544\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image.png 990w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image-300x165.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image-768x422.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image-65x36.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image-225x124.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2022\/04\/2022-04-24-21-16-57-image-350x192.png 350w\" sizes=\"auto, (max-width: 990px) 100vw, 990px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.27: Main scenario<\/figcaption><\/figure>\n<table class=\"grid\" style=\"border-collapse: collapse; width: 100%; height: 75px;\">\n<caption>Table 3.5: Addressing Table<\/caption>\n<tbody>\n<tr style=\"height: 15px;\">\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Device<\/th>\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Configuration<\/th>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">PaloAlto-1<\/td>\n<td style=\"width: 50%; height: 15px;\">management: 192.168.0.1\/24<br \/>\nEthernet1\/1: 10.0.0.1\/24<br \/>\nEthernet1\/2: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Internal (WordPress)<\/td>\n<td style=\"width: 50%; height: 15px;\">eth0: 10.0.0.2\/24 GW: 10.0.0.1<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">KaliLinux2019.3-1<\/td>\n<td style=\"width: 50%; height: 15px;\">eth0: DHCP<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Management<\/td>\n<td style=\"width: 50%; height: 15px;\">eth0: 192.168.0.2\/24<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table class=\"grid\" style=\"border-collapse: collapse; width: 100%; height: 60px;\">\n<caption>Table 3.6: Zone Configuration<\/caption>\n<tbody>\n<tr style=\"height: 15px;\">\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Zone<\/th>\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Interface<\/th>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Inside<\/td>\n<td style=\"width: 50%; height: 15px;\">Ethernet1\/1<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Outside<\/td>\n<td style=\"width: 50%; height: 15px;\">Ethernet1\/2<\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">VPN<\/td>\n<td style=\"width: 50%; height: 15px;\">Tunnel.1<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 style=\"page-break-before: always;\">Create a Tunnel Interface<\/h2>\n<p>Under <strong>Network &gt; Interfaces<\/strong> in the Tunnel tab, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-189 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1.jpg\" alt=\"Creating a Tunnel\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem1-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.28: Creating a Tunnel<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the new window, change the virtual router to default, and the security zone to the VPN zone.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-190 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2.jpg\" alt=\"Tunnel Interface\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem2-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.29: Tunnel Interface<\/figcaption><\/figure>\n<p>Then click <b>OK<\/b>.<\/p>\n<h2 style=\"page-break-before: always;\">Enable User ACL for a Zone<\/h2>\n<p>Under <strong>Network &gt; Zone<\/strong>, click the VPN zone.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-191 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3.jpg\" alt=\"Create a VPN Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem3-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.30: Create a VPN Zone<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">Tick the <strong>Enable user identification<\/strong> box.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-192 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4.jpg\" alt=\"Enable User Identification under VPN Zone\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem4-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.31: Enable User Identification under VPN Zone<\/figcaption><\/figure>\n<p>Then press <strong>OK<\/strong>.<\/p>\n<h2 style=\"page-break-before: always;\">Generate Certs<\/h2>\n<p>Under <strong>Device &gt; Certificate Management &gt; Certificates<\/strong>, click\u00a0on <b>Generate.<\/b><\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-193 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5.jpg\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem5-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.32: Generate a certificate<\/figcaption><\/figure>\n<p>Configure these settings in the new window:<\/p>\n<table class=\"grid\" style=\"border-collapse: collapse; width: 100%; height: 60px;\">\n<caption>Table 3.7: Certificate Generation<\/caption>\n<tbody>\n<tr style=\"height: 15px;\">\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Parameters<\/th>\n<th style=\"width: 50%; height: 15px;\" scope=\"col\">Value<\/th>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Certificate Name<\/td>\n<td style=\"width: 50%; height: 15px;\"><em>Cert Name Here<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Common Name<\/td>\n<td style=\"width: 50%; height: 15px;\"><em>The DHCP IP of Ethernet1\/2<\/em><\/td>\n<\/tr>\n<tr style=\"height: 15px;\">\n<td style=\"width: 50%; height: 15px;\">Certificate Authority<\/td>\n<td style=\"width: 50%; height: 15px;\"><em>Tick this box<\/em><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-194 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image.png\" alt=\"Generate a certificate\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image.png 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image-1024x828.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image-768x621.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image-225x182.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-46-16-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.33: Generate a certificate<\/figcaption><\/figure>\n<p>Then click <strong>Generate<\/strong>.<\/p>\n<h2 style=\"page-break-before: always;\">Create an SSL\/TLS Service Profile<\/h2>\n<p>Under <strong>Device &gt; Certificate Management &gt; SSL\/TLS<\/strong> Service Profile, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-195 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6.jpg\" alt=\"Add SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem6-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.34: Add SSL\/TLS Service Profile<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the new window, add the certificate you generated.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-196 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image.png\" alt=\"Configure SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image.png 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image-1024x828.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image-768x621.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image-225x182.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-00-52-33-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.35: Configure SSL\/TLS Service Profile<\/figcaption><\/figure>\n<p>Then click <b>OK<\/b>.<\/p>\n<h2 style=\"page-break-before: always;\">Create a GlobalProtect Portal<\/h2>\n<p>Under <strong>Network &gt; GlobalProtect &gt; Portals<\/strong>, then click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-197 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7.jpg\" alt=\"Add a Portal\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem7-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.36: Add a Portal<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the general tab, set the interface to Ethernet1\/2.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-198 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8.jpg\" alt=\"GlobalProtect Portal Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem8-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.37: GlobalProtect Portal Configuration<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the authentication tab, select SSL\/TLS profile you created in the previous step, then click <strong>Add<\/strong>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-199 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9.jpg\" alt=\"Adding SSL\/TLS Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem9-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.38: Adding SSL\/TLS Profile<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the new window, change the authentication profile, then press <strong>OK<\/strong>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-200 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10.jpg\" alt=\"Adding Authentication Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem10-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.39: Adding Authentication Profile<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the agent tab, in the agent section, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-201 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11.jpg\" alt=\"Adding the agent\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem11-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.40: Adding the agent<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the internal tab in the Internal gateway, click <b>Add.<\/b><\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-202 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12.jpg\" alt=\"Configure Internal Gateway\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem12-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.41: Configure Internal Gateway<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In this window, change the Address to select IP, and in the IPv4 box, type in the IP of Ethernet1\/2.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-203 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a.jpg\" alt=\"Set the IP address for Internal Gateway\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem13a-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.42: Set the IP address for Internal Gateway<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">Press <b>OK<\/b> twice to get back to the agent tab. Then in the trusted root ca section, add your generated cert, and tick the box to install in local root certificate store.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-204 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image.png\" alt=\"Add the Root CA certificate\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image.png 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image-1024x828.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image-768x621.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image-225x182.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-26-39-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.43: Add the Root CA certificate<\/figcaption><\/figure>\n<p>Then press <b>OK<\/b>.<\/p>\n<h2 style=\"page-break-before: always;\">Create a GlobalProtect Gateway<\/h2>\n<p>Under <strong>Network &gt; GlobalProtect &gt; Gateways<\/strong>, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-205 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14.jpg\" alt=\"Add a Gateway\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem14-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.44: Add a Gateway<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the general tab, set the interface to Ethernet1\/2.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-206 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image.png\" alt=\"GlobalProtect Gateway Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image.png 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image-1024x828.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image-768x621.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image-225x182.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-35-57-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.45: GlobalProtect Gateway Configuration<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the Authentication tab, add your <strong>SSL\/TLS<\/strong> profile, then click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-207 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15.jpg\" alt=\"SSL\/TLS Service Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem15-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.46: SSL\/TLS Service Profile<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In the new window, select your authentication profile, then click <b>OK.<\/b><\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-208 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16.jpg\" alt=\"Authentication Profile\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem16-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.47: Authentication Profile<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">Under the agent tab, in tunnel settings, tick the tunnel mode checkbox and select the tunnel you made.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-209 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17.jpg\" alt=\"Tunnel Mode and Interface\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem17-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.48: Tunnel Mode and Interface<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In client settings, click <b>Add<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-210 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18.jpg\" alt=\"Client Settings\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem18-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.49: Client Settings<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">Make sure the <strong>Any<\/strong> checkbox is ticked on top of the OS category, then press <b>OK<\/b>.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-211 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19.jpg\" alt=\"Select Client as Any\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem19-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.50: Select Client as Any<\/figcaption><\/figure>\n<p style=\"page-break-before: always;\">In client IP pool settings, add an IP pool range of this:<\/p>\n<p><span style=\"background-color: #d1d1d1;\"><code>172.16.10.1-172.16.10.10<\/code><\/span><\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-212 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20.jpg\" alt=\"IP Pool Configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20.jpg 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20-300x243.jpg 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20-1024x828.jpg 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20-768x621.jpg 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20-65x53.jpg 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20-225x182.jpg 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/Rem20-350x283.jpg 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.51: IP Pool Configuration<\/figcaption><\/figure>\n<p>Then press <b>OK<\/b>. Don&#8217;t forget to commit the configuration!<\/p>\n<h2 style=\"page-break-before: always;\">Install the GlobalProtect Client on Kali<\/h2>\n<p>Open up a terminal window and run the following commands:<\/p>\n<div class=\"textbox shaded\"><code>#curl -L https:\/\/bit.ly\/32Ljx1y --output GP.deb<\/code><br \/>\n<code>#sudo dpkg -i GP.deb<\/code><br \/>\n<code>#globalprotect connect -p [IP of Palo Alto Ethernet1\/2 Here]<\/code><\/div>\n<p>When connecting, it will show an error about validation. Type in y then press enter.<\/p>\n<p>It will also ask for your username and password. Enter the one you created prior.<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-213 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image.png\" alt=\"Installing GlobalProtect on Kali Linux\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image.png 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image-1024x828.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image-768x621.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image-225x182.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-45-47-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.52: Installing GlobalProtect on Kali Linux<\/figcaption><\/figure>\n<h2 style=\"page-break-before: always;\">Test Remote Access VPN<\/h2>\n<p>On Kali, after connecting to GlobalProtect, navigate to the IP of the WordPress Server (Internal).<\/p>\n<figure id=\"attachment_214\" aria-describedby=\"caption-attachment-214\" style=\"width: 1026px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-214 size-full\" src=\"https:\/\/opentextbc.ca\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image.png\" alt=\"Verify your configuration\" width=\"1026\" height=\"830\" srcset=\"https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image.png 1026w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image-300x243.png 300w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image-1024x828.png 1024w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image-768x621.png 768w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image-65x53.png 65w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image-225x182.png 225w, https:\/\/opentextbc.ca\/paloalto\/wp-content\/uploads\/sites\/445\/2023\/11\/2022-04-25-01-50-02-image-350x283.png 350w\" sizes=\"auto, (max-width: 1026px) 100vw, 1026px\" \/><figcaption id=\"caption-attachment-214\" class=\"wp-caption-text\">Figure 3.53: Verify your configuration<\/figcaption><\/figure>\n<p>If everything was correct, it should display the WordPress site!<\/p>\n","protected":false},"author":124,"menu_order":2,"template":"","meta":{"pb_show_title":"on","pb_short_title":"","pb_subtitle":"","pb_authors":[],"pb_section_license":""},"chapter-type":[],"contributor":[],"license":[],"class_list":["post-215","chapter","type-chapter","status-publish","hentry"],"part":159,"_links":{"self":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters"}],"about":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/types\/chapter"}],"author":[{"embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/users\/124"}],"version-history":[{"count":1,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/215\/revisions"}],"predecessor-version":[{"id":216,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/215\/revisions\/216"}],"part":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/parts\/159"}],"metadata":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapters\/215\/metadata\/"}],"wp:attachment":[{"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/media?parent=215"}],"wp:term":[{"taxonomy":"chapter-type","embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/pressbooks\/v2\/chapter-type?post=215"},{"taxonomy":"contributor","embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/contributor?post=215"},{"taxonomy":"license","embeddable":true,"href":"https:\/\/opentextbc.ca\/paloalto\/wp-json\/wp\/v2\/license?post=215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}