PA-3260 GP VPN & NAT
Budget: ₹600 – ₹1,500 INR
I need a clean, working GlobalProtect remote-access VPN on my Palo Alto Networks PA-3260. The plan is simple:
• Local database authentication with standard username/password logins—no external Radius or LDAP.
• Split-tunnel design so only traffic destined for our corporate subnets crosses the tunnel; all other internet traffic stays local to the user.
• Two static 1:1 NAT rules for internal servers, complete with the matching security and U-Turn policies.
You’ll build the portal and gateway, set the appropriate agent configurations, create the local user accounts, specify the split-tunnel include routes, and test from a Windows or macOS GlobalProtect client. Once that works, we’ll verify inbound and outbound reachability for the NATed servers.
Acceptance criteria
1. I can sign in through GlobalProtect with a local user and reach internal resources while internet traffic breaks out locally.
2. Each internal server is reachable externally on its new public IP, and it can initiate outbound sessions without issues.
I can give you GUI or CLI access in a shared session, or you can supply step-by-step commands for me to paste. A brief hand-over document so I can reproduce the setup in the future will wrap things up.
Let me know when you can start.
• Local database authentication with standard username/password logins—no external Radius or LDAP.
• Split-tunnel design so only traffic destined for our corporate subnets crosses the tunnel; all other internet traffic stays local to the user.
• Two static 1:1 NAT rules for internal servers, complete with the matching security and U-Turn policies.
You’ll build the portal and gateway, set the appropriate agent configurations, create the local user accounts, specify the split-tunnel include routes, and test from a Windows or macOS GlobalProtect client. Once that works, we’ll verify inbound and outbound reachability for the NATed servers.
Acceptance criteria
1. I can sign in through GlobalProtect with a local user and reach internal resources while internet traffic breaks out locally.
2. Each internal server is reachable externally on its new public IP, and it can initiate outbound sessions without issues.
I can give you GUI or CLI access in a shared session, or you can supply step-by-step commands for me to paste. A brief hand-over document so I can reproduce the setup in the future will wrap things up.
Let me know when you can start.