<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Internal Gateway - Non-tunnel mode - does it provide encryption? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-gateway-non-tunnel-mode-does-it-provide/m-p/367365#M655</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151796"&gt;@SergGur&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you choose not to tunnel the traffic back to the gateway the only thing you are doing is HIP and User-ID through GlobalProtect. It doesn't add any form of encryption and the traffic outside of agent checks never hits the internal gateway.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Dec 2020 18:31:26 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2020-12-04T18:31:26Z</dc:date>
    <item>
      <title>GlobalProtect Internal Gateway - Non-tunnel mode - does it provide encryption?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-gateway-non-tunnel-mode-does-it-provide/m-p/367319#M654</link>
      <description>&lt;DIV&gt;Hello Experts,&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Can you please clarify if Non-tunnel mode provide packet encryption, or just HIP/User-ID for the gateway?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Does the traffic goes in from GlobalProtect&amp;nbsp; (laptop) to GlobalProtect gateway (firewall) in non-tunnel mode setup?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;If it is encrypted, how much of IP header retained, is it just IP or ports are in clear as well?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;It is not clear from the documentation:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;Internal&lt;/STRONG&gt; —An internal gateway is an interface on the internal network that is configured as a GlobalProtect gateway and applies security policies for internal resource access. When used in conjunction with User-ID and/or HIP checks, an internal gateway can be used to provide a secure, accurate method of identifying and controlling traffic based on user and/or device state. Internal gateways are useful in sensitive environments where authenticated access to critical resources is required. &lt;EM&gt;&lt;STRONG&gt;You can configure an internal gateway in either tunnel mode or non-tunnel mode&lt;/STRONG&gt;&lt;/EM&gt;. The GlobalProtect app connects to the internal gateway after performing internal host detection to determine the location of the endpoint.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;References:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-gateways/globalprotect-gateway-concepts/types-of-gateways.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-gateways/globalprotect-gateway-concepts/types-of-gateways.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/globalprotect/10-0/globalprotect-admin/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 14:38:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-gateway-non-tunnel-mode-does-it-provide/m-p/367319#M654</guid>
      <dc:creator>SergGur</dc:creator>
      <dc:date>2020-12-04T14:38:40Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Internal Gateway - Non-tunnel mode - does it provide encryption?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-gateway-non-tunnel-mode-does-it-provide/m-p/367365#M655</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/151796"&gt;@SergGur&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If you choose not to tunnel the traffic back to the gateway the only thing you are doing is HIP and User-ID through GlobalProtect. It doesn't add any form of encryption and the traffic outside of agent checks never hits the internal gateway.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 18:31:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-gateway-non-tunnel-mode-does-it-provide/m-p/367365#M655</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-12-04T18:31:26Z</dc:date>
    </item>
  </channel>
</rss>

