<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic how to enforce user to connect to GP internal GW in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205133#M6383</link>
    <description>&lt;P&gt;Hi Expert,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup an internal GP GW to get user-id, which works fine. But now the question is how to enforce users to connect to it once in office. On GP portal, I set &lt;SPAN data-olk-copy-source="MessageBody"&gt;&amp;lt;Enforce GlobalProtect for user access&amp;gt;&amp;nbsp;&lt;/SPAN&gt; to Yes , but it is not working. Tried both&amp;nbsp;&lt;/P&gt;
&lt;DIV data-olk-copy-source="MessageBody"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;pre-logon always on&amp;gt; and&amp;nbsp;&amp;lt;user-logon always on&amp;gt;.&lt;/DIV&gt;
&lt;DIV data-olk-copy-source="MessageBody"&gt;Please let me know any way can get it resolved.&lt;/DIV&gt;</description>
    <pubDate>Thu, 23 Jan 2025 05:48:03 GMT</pubDate>
    <dc:creator>C.Gao140612</dc:creator>
    <dc:date>2025-01-23T05:48:03Z</dc:date>
    <item>
      <title>how to enforce user to connect to GP internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205133#M6383</link>
      <description>&lt;P&gt;Hi Expert,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have setup an internal GP GW to get user-id, which works fine. But now the question is how to enforce users to connect to it once in office. On GP portal, I set &lt;SPAN data-olk-copy-source="MessageBody"&gt;&amp;lt;Enforce GlobalProtect for user access&amp;gt;&amp;nbsp;&lt;/SPAN&gt; to Yes , but it is not working. Tried both&amp;nbsp;&lt;/P&gt;
&lt;DIV data-olk-copy-source="MessageBody"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;lt;pre-logon always on&amp;gt; and&amp;nbsp;&amp;lt;user-logon always on&amp;gt;.&lt;/DIV&gt;
&lt;DIV data-olk-copy-source="MessageBody"&gt;Please let me know any way can get it resolved.&lt;/DIV&gt;</description>
      <pubDate>Thu, 23 Jan 2025 05:48:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205133#M6383</guid>
      <dc:creator>C.Gao140612</dc:creator>
      <dc:date>2025-01-23T05:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: how to enforce user to connect to GP internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205227#M6388</link>
      <description>&lt;P&gt;make sure the internal gateway has tunnel mode enabled, else the agent won't connect to it:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1737664451172.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65426i7D29FC4E6A99763F/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1737664451172.png" alt="reaper_0-1737664451172.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jan 2025 20:34:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205227#M6388</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-01-23T20:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: how to enforce user to connect to GP internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205251#M6389</link>
      <description>&lt;P&gt;Thanks a lot for the reply. So this is internal GW with tunnel mode. And I just need to setup a tunnel interface and if need to configure the ip pool ? Or the client just use the DHCP assigned internal ip address.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 01:06:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205251#M6389</guid>
      <dc:creator>C.Gao140612</dc:creator>
      <dc:date>2025-01-24T01:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: how to enforce user to connect to GP internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205328#M6395</link>
      <description>&lt;P&gt;Create an IP pool and also do the split tunneling including all internal network subnets and fqdn's. This will make GP to only forward office network traffic through it's virtual Network adapter and the rest outside internet traffic will be passed through physical Network adapter.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jan 2025 13:12:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205328#M6395</guid>
      <dc:creator>trewale</dc:creator>
      <dc:date>2025-01-24T13:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to enforce user to connect to GP internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205432#M6401</link>
      <description>&lt;P&gt;I think you referring to Internal host detection where users always connect to the internal gateway when in the office. To achieve this you need a PTR record configured on the firewall that must be resolved for internal users.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Let me know if this is the requirement or if I have misunderstood your query.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 02:55:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205432#M6401</guid>
      <dc:creator>arusharma</dc:creator>
      <dc:date>2025-01-27T02:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: how to enforce user to connect to GP internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205509#M6405</link>
      <description>&lt;P&gt;Hi Arusharma, the internal gw is working fine , but question is how to enforce users to connect to GP internal GW by default when they are in office.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Already opened a TAC case, but suggested to use HIP, I do not think that is related.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 18:56:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205509#M6405</guid>
      <dc:creator>C.Gao140612</dc:creator>
      <dc:date>2025-01-27T18:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: how to enforce user to connect to GP internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205519#M6406</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Restrict the default LAN IP that is received by the client to only be able to connect to a few things:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://skrzsecurity.net/zero-trust#:~:text=get%20to%20it.-,Architecture,-%3A" target="_blank"&gt;https://skrzsecurity.net/zero-trust#:~:text=get%20to%20it.-,Architecture,-%3A&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 20:47:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-enforce-user-to-connect-to-gp-internal-gw/m-p/1205519#M6406</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-01-27T20:47:41Z</dc:date>
    </item>
  </channel>
</rss>

