<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Pre-logon does not consistently switch IP pools in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/484049#M2715</link>
    <description>&lt;P&gt;We also&amp;nbsp;&lt;SPAN&gt;found that for Windows machines, there was a tunnel rename issue&amp;nbsp; - and our client machines were "holding on" to their IP from the pre-logon pool even though&amp;nbsp;they were no longer connected as pre-logon.&amp;nbsp; So we changed the default value of '-1'&amp;nbsp; &amp;nbsp;(under network, portals, and then under the app section for the pre-logon agent configuration) for the "Pre-Logon Tunnel Rename Timeout (sec) (Windows Only)" to 0 instead. It works since we did that.&amp;nbsp; Our SE also sent us a note about it that&amp;nbsp; have not looked into yet - could explain why we needed that.&lt;BR /&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 01 May 2022 20:32:10 GMT</pubDate>
    <dc:creator>JPMacNeil</dc:creator>
    <dc:date>2022-05-01T20:32:10Z</dc:date>
    <item>
      <title>Global Protect Pre-logon does not consistently switch IP pools</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/343757#M339</link>
      <description>&lt;P&gt;We have a client with Global Protect Pre-logon, which assigns different IP pools to the Pre-logon user than to the known client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sometimes we see the connection get the Pri-logon IP and then switch to the known client IP, but other times we see it hang onto the Pre-logon address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall PAN-OS 8.1.15-h3&lt;/P&gt;&lt;P&gt;Client version 5.1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any suggestions on where to look to figure out why it is inconsistent are appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Aug 2020 15:59:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/343757#M339</guid>
      <dc:creator>jfritchey</dc:creator>
      <dc:date>2020-08-13T15:59:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Pre-logon does not consistently switch IP pools</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/352905#M462</link>
      <description>&lt;P&gt;we have same problem here but with split-tunnel since we have same IP pool for Pre-logon and actual users.&lt;/P&gt;&lt;P&gt;a workaround is to manually refresh the connection after actual user logon&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any solution ??&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 09:27:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/352905#M462</guid>
      <dc:creator>Mohammad.Qasem</dc:creator>
      <dc:date>2020-09-30T09:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Pre-logon does not consistently switch IP pools</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/352931#M463</link>
      <description>&lt;P&gt;We concluded that Global Protect was behaving as designed since the documentation we found indicated that for Windows machines, the tunnel would be renamed from pre-logon to the known user. The client changed his rulebase to apply rules based on user-id rather than ip range and as far as I know, this is working. It is not entirely satisfying, but as far as I can tell, this may just be the way gp works.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 10:22:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/352931#M463</guid>
      <dc:creator>jfritchey</dc:creator>
      <dc:date>2020-09-30T10:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Pre-logon does not consistently switch IP pools</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/484049#M2715</link>
      <description>&lt;P&gt;We also&amp;nbsp;&lt;SPAN&gt;found that for Windows machines, there was a tunnel rename issue&amp;nbsp; - and our client machines were "holding on" to their IP from the pre-logon pool even though&amp;nbsp;they were no longer connected as pre-logon.&amp;nbsp; So we changed the default value of '-1'&amp;nbsp; &amp;nbsp;(under network, portals, and then under the app section for the pre-logon agent configuration) for the "Pre-Logon Tunnel Rename Timeout (sec) (Windows Only)" to 0 instead. It works since we did that.&amp;nbsp; Our SE also sent us a note about it that&amp;nbsp; have not looked into yet - could explain why we needed that.&lt;BR /&gt;"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 May 2022 20:32:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-pre-logon-does-not-consistently-switch-ip-pools/m-p/484049#M2715</guid>
      <dc:creator>JPMacNeil</dc:creator>
      <dc:date>2022-05-01T20:32:10Z</dc:date>
    </item>
  </channel>
</rss>

