<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect idle timeout in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-idle-timeout/m-p/540221#M3978</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hello all,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would like to know your feedback with some requirements which I have to configure a GlobalProtect VPN to be used by mobile devices:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1- Split tunneling: Configured and working properly, mobile devices using this VPN are sending through the VPN only the traffic of some specific subnets.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2- Specific addressing based on SO: I’ve also deployed this feature successfully.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3- APP/FQDN based VPN: The VPN is only connected if the user tries to use or open an specific APP or URL. This has also been deployed successfully thanks to our MDM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4- Automatic disconnection if the user has not sent traffic through the VPN after 20 minutes: Here I’m stuck…. the idle timeout should help me with this requirement, but never reaches…. GlobalProtect provides a DNS server which is behind the VPN. Because Split DNS is not a valid feature under iOS and Android… once the VPN comes UP all DNS queries goes through the VPN….&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So I would appreciate if you could provide me some help with the point number 4….Probably I should use another approach because on this case split dns is not an option, I’m open to new approaches.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2023 17:07:28 GMT</pubDate>
    <dc:creator>pasp_997</dc:creator>
    <dc:date>2023-04-26T17:07:28Z</dc:date>
    <item>
      <title>GlobalProtect idle timeout</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-idle-timeout/m-p/540221#M3978</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello all,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would like to know your feedback with some requirements which I have to configure a GlobalProtect VPN to be used by mobile devices:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1- Split tunneling: Configured and working properly, mobile devices using this VPN are sending through the VPN only the traffic of some specific subnets.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2- Specific addressing based on SO: I’ve also deployed this feature successfully.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3- APP/FQDN based VPN: The VPN is only connected if the user tries to use or open an specific APP or URL. This has also been deployed successfully thanks to our MDM.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;4- Automatic disconnection if the user has not sent traffic through the VPN after 20 minutes: Here I’m stuck…. the idle timeout should help me with this requirement, but never reaches…. GlobalProtect provides a DNS server which is behind the VPN. Because Split DNS is not a valid feature under iOS and Android… once the VPN comes UP all DNS queries goes through the VPN….&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So I would appreciate if you could provide me some help with the point number 4….Probably I should use another approach because on this case split dns is not an option, I’m open to new approaches.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance!!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2023 17:07:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-idle-timeout/m-p/540221#M3978</guid>
      <dc:creator>pasp_997</dc:creator>
      <dc:date>2023-04-26T17:07:28Z</dc:date>
    </item>
  </channel>
</rss>

