Configure GlobalProtect on VeloCloud
2793
Created On 12/29/20 01:54 AM - Last Modified 09/15/21 21:26 PM
Symptom
- Configuration of VM-Series Firewall to work with GlobalProtect VPN on VeloCloud fails and connection is down.
- Other physical interfaces i.e. eth1/3-eth1/7 are not configurable in VeloCloud. Maximum number of NIC can be configured on this platform: 2
Environment
- Platform: PA-VM on VeloCloud by VMWare
- PAN-OS/Plugin Version: Any
- Deployment: Existing/New
Cause
VeloCloud does NOT support layer 3 interfaces but only vwire mode.
Resolution
Currently GlobalProtect is only supported by layer 3 interface type due to which we cannot use VeloCloud for GlobalProtect. Possible solutions are below.
- Request Account Team to submit a feature request.
- Use Public or Private cloud platforms which supports Layer 3 deployment such as AWS, GCP, Azure etc...
- Use Prisma Access (GlobalProtect for cloud solutions)