<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect blocking access internet using browser in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616092#M6069</link>
    <description>&lt;P&gt;Try to access Internet from outside the company.&lt;/P&gt;
&lt;P&gt;Then check Palo logs (Monitor &amp;gt; Traffic).&lt;/P&gt;
&lt;P&gt;Do you see sessions from Mac GlobalProtect IP towards Internet?&lt;/P&gt;
&lt;P&gt;Is action allow?&lt;/P&gt;
&lt;P&gt;Is source nat applied (you can check session details if you click on a mag glass on left side of traffic log).&lt;/P&gt;</description>
    <pubDate>Mon, 04 Nov 2024 19:09:11 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2024-11-04T19:09:11Z</dc:date>
    <item>
      <title>GlobalProtect blocking access internet using browser</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616075#M6066</link>
      <description>&lt;P&gt;My company uses GlobalProtect VPN and I have a problem that needs help connecting Globalprotect on MacOS.&lt;/P&gt;&lt;P&gt;On the company device, it requires a GlobalProtect VPN connection to access company systems, allowed applications. But on MacOS, every time the employee takes the device out of the office and uses a wifi network other than internal wifi, all websites accessed by browser cannot be accessed, it reports an error: This site can't be reached. However, all applications installed on the device still connect normally such as: Teams, Outlook, Lark,...etc. I ping and nslookup the website, the IP has a signal but cannot access. I have tried many ways such as: setting the router's fixed DNS, Google DNS, AWS DNS, using the command sudo dscacheutil -flushcache; sudo killall -HUP mDNSResponder to clear DNS cache on MacOS, disable connect and reconnect, refresh VPN connection and uninstall GlobalProtect then reinstall but all failed.&lt;/P&gt;&lt;P&gt;The only way is to wait for the device for about 1-2 hours and it will automatically access the websites again.&lt;/P&gt;&lt;P&gt;The same thing happens when an employee successfully accesses the website using an external wifi and the next day reconnects to the internal wifi but still cannot access the website using the browser.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 16:21:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616075#M6066</guid>
      <dc:creator>binn698</dc:creator>
      <dc:date>2024-11-04T16:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect blocking access internet using browser</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616077#M6067</link>
      <description>&lt;P&gt;You manage Palo firewall in the company?&lt;/P&gt;
&lt;P&gt;Do devices inside the network establish IPSec tunnel or have Internal Host Detection enabled?&lt;/P&gt;
&lt;P&gt;Does GlobalProtect connect while using external wifi?&lt;/P&gt;
&lt;P&gt;Do website names resolve to IP while using external wifi?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 16:30:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616077#M6067</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-11-04T16:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect blocking access internet using browser</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616078#M6068</link>
      <description>&lt;P&gt;You manage Palo firewall in the company?&lt;BR /&gt;- Yes I can access and check, basic configuration on the firewall, but I don't fully understand how it works.&lt;BR /&gt;Do devices inside the network establish IPSec tunnel or have Internal Host Detection enabled?&lt;BR /&gt;- Sorry I don't know where to check it from. Can you give me more information so I can check it.&lt;BR /&gt;Does GlobalProtect connect while using external wifi?&lt;BR /&gt;- GlobalProtect must always be connected to be able to access the internet from the company device. If the connection fails or is connected, the internet cannot be accessed.&lt;BR /&gt;Do website names resolve to IP while using external wifi?&lt;BR /&gt;- Yes. I use nslookup from the website to resolve to IP with external websites as well as internal websites.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 16:40:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616078#M6068</guid>
      <dc:creator>binn698</dc:creator>
      <dc:date>2024-11-04T16:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect blocking access internet using browser</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616092#M6069</link>
      <description>&lt;P&gt;Try to access Internet from outside the company.&lt;/P&gt;
&lt;P&gt;Then check Palo logs (Monitor &amp;gt; Traffic).&lt;/P&gt;
&lt;P&gt;Do you see sessions from Mac GlobalProtect IP towards Internet?&lt;/P&gt;
&lt;P&gt;Is action allow?&lt;/P&gt;
&lt;P&gt;Is source nat applied (you can check session details if you click on a mag glass on left side of traffic log).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Nov 2024 19:09:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616092#M6069</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2024-11-04T19:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect blocking access internet using browser</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616114#M6071</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When using the internet outside the company and GlobalProtect VPN connected, I saw traffic from the device going to the internet such as: ms-team, ms-outlook-web,... and many other applications installed on the device. I was sure that those traffics were allowed, I also created a separate rule allow any any any to test but still had to wait 1,2 hours later for the device to be able to access the internet using the browser.&lt;BR /&gt;One thing I saw was that at that time, the traffic log called back to my company's DNS server a lot, more than the traffic going out to the internet. All of them were allowed.&lt;/P&gt;&lt;P&gt;This only happens on MacOS devices, my company has over 400 Windows devices and GlobalProtect works fine. About 20 MacOS devices for the dev team have the same problem.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Nov 2024 02:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-blocking-access-internet-using-browser/m-p/616114#M6071</guid>
      <dc:creator>binn698</dc:creator>
      <dc:date>2024-11-05T02:22:30Z</dc:date>
    </item>
  </channel>
</rss>

