<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Giving users the ability to select a different gateway in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543397#M4043</link>
    <description>&lt;P&gt;I think you might be on to something! Looking at the existing troubleshooting profile, the manual box is checked for all of the gateways. I was not aware of the setting:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_0-1685052944859.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50344iEDDCC759A11D7CCB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_0-1685052944859.png" alt="StephenGilder_0-1685052944859.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I've cloned the default profile that most users hit and have put just my login on there.&lt;BR /&gt;I've now added that manual check box to all the gateways and looks like that did achieve the goal of giving the option to choose manually with out giving the option to disconnect.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_2-1685054251797.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50346i56174E0901495B06/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_2-1685054251797.png" alt="StephenGilder_2-1685054251797.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I will have to do some more testing to confirm whether or not it truly does stay always on, but I think it will since we have pre-login&amp;nbsp; connections enabled.&lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2023 22:39:48 GMT</pubDate>
    <dc:creator>StephenGilder</dc:creator>
    <dc:date>2023-05-25T22:39:48Z</dc:date>
    <item>
      <title>Giving users the ability to select a different gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543386#M4041</link>
      <description>&lt;P&gt;We have multiple gateways in our environment. Our default agent profile has always on configured. Users are balanced across the gateways.&lt;/P&gt;
&lt;P&gt;We have a troubleshooting profile that gives users the option to disconnect and choose to try and switch to a different gateway.&lt;BR /&gt;My question is that I would like to configure a profile that is always on but gives the user the option to switch gateways but does not give the option to disable/disconnect from VPN.&lt;BR /&gt;Is this possible? If so how?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The reason for this is if users get on to a gateway that doesn't work well for them for what ever reason, they are hitting refresh multiple times until they eventually get to a gateway that works better for them geographically.&lt;BR /&gt;&lt;BR /&gt;Network-&amp;gt;Global Protect-&amp;gt;Portals-&amp;gt;Agent-&amp;gt;App-&amp;gt;&lt;BR /&gt;Configuration: 'Allow user to disconnect GlobalProtect App (Always-on mode)'&lt;BR /&gt;This is currently set to Disallow.&lt;BR /&gt;The Troubleshooting profile has this set to 'allow with comments'&lt;BR /&gt;The ability to choose the gateway seems to be a side effect of allowing it to be disabled.&lt;BR /&gt;I don't want to allow disconnect, however, I do want to allow the option shown below to choose a gateway, but I do not see that as an option in the list of configuration items in this area of the config.&lt;BR /&gt;Images while connected to the troubleshooting profile:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_0-1685048856353.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50340i075C5530F1D0A574/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_0-1685048856353.png" alt="StephenGilder_0-1685048856353.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_2-1685049001421.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50342i0D768A528BFB6FF7/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_2-1685049001421.png" alt="StephenGilder_2-1685049001421.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This is what the normal user agent profile looks like. The Gateway selection is not shown, nor is the disable option:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_3-1685049646305.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50343i128336232129DF60/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_3-1685049646305.png" alt="StephenGilder_3-1685049646305.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 21:22:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543386#M4041</guid>
      <dc:creator>StephenGilder</dc:creator>
      <dc:date>2023-05-25T21:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: Giving users the ability to select a different gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543390#M4042</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/216004"&gt;@StephenGilder&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want the user to manually select a gateway, you change the Network &amp;gt; GlobalProtect &amp;gt; Portals &amp;gt; [edit portal] &amp;gt; Agent &amp;gt; [edit config] &amp;gt; External &amp;gt; [edit gateway] &amp;gt; Priority &amp;gt; Manual only.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can combine Manual-only with Always On but GP will not connect until the user selects a gateway.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am curious if that combination allows the user to switch gateways after they connect.&amp;nbsp; Would you mind testing?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 21:45:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543390#M4042</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-25T21:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Giving users the ability to select a different gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543397#M4043</link>
      <description>&lt;P&gt;I think you might be on to something! Looking at the existing troubleshooting profile, the manual box is checked for all of the gateways. I was not aware of the setting:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_0-1685052944859.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50344iEDDCC759A11D7CCB/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_0-1685052944859.png" alt="StephenGilder_0-1685052944859.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I've cloned the default profile that most users hit and have put just my login on there.&lt;BR /&gt;I've now added that manual check box to all the gateways and looks like that did achieve the goal of giving the option to choose manually with out giving the option to disconnect.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_2-1685054251797.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50346i56174E0901495B06/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_2-1685054251797.png" alt="StephenGilder_2-1685054251797.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I will have to do some more testing to confirm whether or not it truly does stay always on, but I think it will since we have pre-login&amp;nbsp; connections enabled.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 22:39:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543397#M4043</guid>
      <dc:creator>StephenGilder</dc:creator>
      <dc:date>2023-05-25T22:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Giving users the ability to select a different gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543400#M4044</link>
      <description>&lt;P&gt;I looked a little closer at the link you provided. The 'Manual Only' you mentioned is for the Priority.(in blue)&amp;nbsp; However, what I found was a check box that lets the user manually select a gateway. That option appears to be the one I needed (In Yellow)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StephenGilder_3-1685054653129.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/50347i95F3F52535262072/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="StephenGilder_3-1685054653129.png" alt="StephenGilder_3-1685054653129.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 22:44:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543400#M4044</guid>
      <dc:creator>StephenGilder</dc:creator>
      <dc:date>2023-05-25T22:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: Giving users the ability to select a different gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543406#M4045</link>
      <description>&lt;P&gt;Excellent!&amp;nbsp; Thank you for the clarification.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you able to switch gateways once connected?&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 22:55:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543406#M4045</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-05-25T22:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Giving users the ability to select a different gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543409#M4046</link>
      <description>&lt;P&gt;Yes. The VPN comes on automatically when the computer boots up and I login and once connected to what ever gateway gets picked based on priority, I am able to hit the drop down and choose a different gateway to connect to.&lt;BR /&gt;Works exactly like what I was looking to do.&lt;BR /&gt;Thank You very much for pointing me in the right direction!&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 23:06:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/giving-users-the-ability-to-select-a-different-gateway/m-p/543409#M4046</guid>
      <dc:creator>StephenGilder</dc:creator>
      <dc:date>2023-05-25T23:06:42Z</dc:date>
    </item>
  </channel>
</rss>

