<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect client cant access internal resources in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-cant-access-internal-resources/m-p/512355#M3088</link>
    <description>&lt;P&gt;PAN OS 8.1.22 / GlobalProtect Agent 6.0.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(1) GlobalProtect has no issue connecting to portal/gateway (Dell Latitude, Windows 11)&lt;/P&gt;
&lt;P&gt;(2) Gateway Access Route (split tunnel)(No direct access to local network is UNTICK) has access to 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;(3) VPN users authenticated are assign 10.0.1.1-40 address&lt;/P&gt;
&lt;P&gt;(4) DNS assignment is 192.168.10.10/24 (dc-01.internal.site) - once connected via GP&lt;/P&gt;
&lt;P&gt;(5) Internal servers/pcs are manually assign 192.168.10.0/24 address&lt;/P&gt;
&lt;P&gt;(6) Internal servers includes webserver (192.168.10.60), email (192.168.10.90), file transfer (192.168.10.91), DC also DNS (192.168.10.10) and other workstation (PCs)&lt;/P&gt;
&lt;P&gt;(7) These servers could be ping and reach via their dns names or IP addresses when GP is connected&lt;/P&gt;
&lt;P&gt;(8) There is no extra configuration to the 'hosts' file from the GP Client PCs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;CHANGES&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(1) I configured and added a VM Hypervisor 6 on a Dell PowerEdge R230&lt;/P&gt;
&lt;P&gt;(2) Management of Virtual Host is via GBport 1 with IP 192.168.1.180 (connected to internet)&lt;/P&gt;
&lt;P&gt;(3) GBPort 2 is connected to 'Internal Network' (as described above to the network 192.168.10.0/24)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GBPort 2 is passthru to the Internal Network to be used by virtual machines&lt;/P&gt;
&lt;P&gt;(4) I added 2 virtual machines ZIMBRA (192.168.10.81) &amp;amp; OWNCLOUD (192.168.10.80)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - the machines has 2 network adapters assign (internet and internal)&lt;/P&gt;
&lt;P&gt;(5) From these 2 machines i can access the internet and INTERNAL network, no problem&lt;/P&gt;
&lt;P&gt;(6) I have add the DNS of these 2 machines to the DNS server&lt;/P&gt;
&lt;P&gt;(7) From a workstation (within the INTERNAL network), i can ping both Zimbra/Owncloud via their IP and Domain names&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - i can also access the webpage of Zimbra and Owncloud&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - can send and receive emails&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - can download and upload from/to Owncloud server&lt;/P&gt;
&lt;P&gt;(8) Firewall policy had been amended to include IP address of Zimbra and Owncloud&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;PROBLEM&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;- however, both Zimbra and Owncloud servers could not be access from GlobalProtect clients (as mentioned above, other resources could be reach)&lt;/P&gt;
&lt;P&gt;- both servers could not be ping or reached&lt;/P&gt;
&lt;P&gt;- nslookup showed dc-01.internal.site and 192.168.10.10 (can be reached)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help will be greatly apprciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Aug 2022 08:18:03 GMT</pubDate>
    <dc:creator>Jee.Khai</dc:creator>
    <dc:date>2022-08-19T08:18:03Z</dc:date>
    <item>
      <title>GlobalProtect client cant access internal resources</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-cant-access-internal-resources/m-p/512355#M3088</link>
      <description>&lt;P&gt;PAN OS 8.1.22 / GlobalProtect Agent 6.0.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(1) GlobalProtect has no issue connecting to portal/gateway (Dell Latitude, Windows 11)&lt;/P&gt;
&lt;P&gt;(2) Gateway Access Route (split tunnel)(No direct access to local network is UNTICK) has access to 0.0.0.0/0&lt;/P&gt;
&lt;P&gt;(3) VPN users authenticated are assign 10.0.1.1-40 address&lt;/P&gt;
&lt;P&gt;(4) DNS assignment is 192.168.10.10/24 (dc-01.internal.site) - once connected via GP&lt;/P&gt;
&lt;P&gt;(5) Internal servers/pcs are manually assign 192.168.10.0/24 address&lt;/P&gt;
&lt;P&gt;(6) Internal servers includes webserver (192.168.10.60), email (192.168.10.90), file transfer (192.168.10.91), DC also DNS (192.168.10.10) and other workstation (PCs)&lt;/P&gt;
&lt;P&gt;(7) These servers could be ping and reach via their dns names or IP addresses when GP is connected&lt;/P&gt;
&lt;P&gt;(8) There is no extra configuration to the 'hosts' file from the GP Client PCs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;CHANGES&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(1) I configured and added a VM Hypervisor 6 on a Dell PowerEdge R230&lt;/P&gt;
&lt;P&gt;(2) Management of Virtual Host is via GBport 1 with IP 192.168.1.180 (connected to internet)&lt;/P&gt;
&lt;P&gt;(3) GBPort 2 is connected to 'Internal Network' (as described above to the network 192.168.10.0/24)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - GBPort 2 is passthru to the Internal Network to be used by virtual machines&lt;/P&gt;
&lt;P&gt;(4) I added 2 virtual machines ZIMBRA (192.168.10.81) &amp;amp; OWNCLOUD (192.168.10.80)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - the machines has 2 network adapters assign (internet and internal)&lt;/P&gt;
&lt;P&gt;(5) From these 2 machines i can access the internet and INTERNAL network, no problem&lt;/P&gt;
&lt;P&gt;(6) I have add the DNS of these 2 machines to the DNS server&lt;/P&gt;
&lt;P&gt;(7) From a workstation (within the INTERNAL network), i can ping both Zimbra/Owncloud via their IP and Domain names&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - i can also access the webpage of Zimbra and Owncloud&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - can send and receive emails&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - can download and upload from/to Owncloud server&lt;/P&gt;
&lt;P&gt;(8) Firewall policy had been amended to include IP address of Zimbra and Owncloud&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;PROBLEM&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;- however, both Zimbra and Owncloud servers could not be access from GlobalProtect clients (as mentioned above, other resources could be reach)&lt;/P&gt;
&lt;P&gt;- both servers could not be ping or reached&lt;/P&gt;
&lt;P&gt;- nslookup showed dc-01.internal.site and 192.168.10.10 (can be reached)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help will be greatly apprciated&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 08:18:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-cant-access-internal-resources/m-p/512355#M3088</guid>
      <dc:creator>Jee.Khai</dc:creator>
      <dc:date>2022-08-19T08:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect client cant access internal resources</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-cant-access-internal-resources/m-p/512356#M3089</link>
      <description>&lt;P&gt;zimbra&lt;/P&gt;
&lt;P&gt;- /etc/hostname = zimbra.internal.site&lt;/P&gt;
&lt;P&gt;- /etc/hosts = 192.168.10.81 zimbra.internal.site&lt;/P&gt;
&lt;P&gt;- /runm/systemd/resolve/resolv.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp; (nameserver 192.168.10.10 / nameserver 192.168.1.1 / search localdomain)&lt;/P&gt;
&lt;P&gt;owncloud&lt;/P&gt;
&lt;P&gt;- /etc/hostname = owncloud.internal.site&lt;/P&gt;
&lt;P&gt;- /etc/hosts = 192.168.10.80 owncloud.internal.site&lt;/P&gt;
&lt;P&gt;- /run/systemd/resolve/resolv.conf&lt;/P&gt;
&lt;P&gt;&amp;nbsp; (nameserver 192.168.10.10 / nameserver 192.168.1.1)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 08:31:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-client-cant-access-internal-resources/m-p/512356#M3089</guid>
      <dc:creator>Jee.Khai</dc:creator>
      <dc:date>2022-08-19T08:31:16Z</dc:date>
    </item>
  </channel>
</rss>

