<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect users not able to use internet when they move to office from Home in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/508517#M2975</link>
    <description>&lt;P&gt;When configuring this, when it comes to portal configuration, do I edit our existing external portal?&amp;nbsp; In the portal configuration assuming im using our existing external portal, do I change the interface to the internal interface/IP?&lt;/P&gt;</description>
    <pubDate>Mon, 11 Jul 2022 21:51:08 GMT</pubDate>
    <dc:creator>emarschang</dc:creator>
    <dc:date>2022-07-11T21:51:08Z</dc:date>
    <item>
      <title>Global Protect users not able to use internet when they move to office from Home</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/437370#M1836</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had configured an GP Portal/Gateway on the firewall. The login method configured on GP is Pre-Logon method and we also had enabled "No Direct Access to local network". The Authentication method used is LDAP. Gateway is configured in Full tunnel mode&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As the user were working from home previously they will be able to access internet only when GP VPN is enabled. Now the users started moving to office and also in office environment they need to connect through GP to access internal network and internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way to configure GP in such an manner that when the user is using his laptop in home he need to connect to GP-VPN to use their system and when they come to office no need to connect to GP-VPN to use their system to access internet and organization internal network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 12:50:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/437370#M1836</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-09-29T12:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect users not able to use internet when they move to office from Home</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/443429#M1932</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can use Internal Gateway as possible solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Oct 2021 12:20:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/443429#M1932</guid>
      <dc:creator>WeidmannIT</dc:creator>
      <dc:date>2021-10-26T12:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect users not able to use internet when they move to office from Home</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/443677#M2076</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, this can be done.&amp;nbsp; In addition to your external gateway, you would configure an internal gateway in non-tunnel mode with Internal Host Detection enabled.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000ClH1" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000ClH1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note in the doc that (1) the trust interface is used, (2) the Agent tab on the gateway is not configured (Tunnel Mode is not checked).&amp;nbsp; As the name implies, no encrypted tunnel is formed between the client and the gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This configuration has the added benefit of providing accurate User-ID inside the network and enforcing HIP checks if configured.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is more info on Internal Host Detection -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab.html&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is more info on types of gateways -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/globalprotect-gateway-concepts/types-of-gateways.html" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-gateways/globalprotect-gateway-concepts/types-of-gateways.html&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 03:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/443677#M2076</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-10-27T03:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect users not able to use internet when they move to office from Home</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/508517#M2975</link>
      <description>&lt;P&gt;When configuring this, when it comes to portal configuration, do I edit our existing external portal?&amp;nbsp; In the portal configuration assuming im using our existing external portal, do I change the interface to the internal interface/IP?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jul 2022 21:51:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-users-not-able-to-use-internet-when-they-move-to/m-p/508517#M2975</guid>
      <dc:creator>emarschang</dc:creator>
      <dc:date>2022-07-11T21:51:08Z</dc:date>
    </item>
  </channel>
</rss>

