<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect Internal Host Detection with Always-On and Enforcement in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1223823#M6573</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72303"&gt;@gkevlin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Pretty much all of your issues are solved with pre-login. What exactly is the issue that is preventing you from enabling it and wanting CBL for the remote-only users; that's the whole point of pre-login and that capability solves the rest of your issues. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Mar 2025 22:00:40 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2025-03-13T22:00:40Z</dc:date>
    <item>
      <title>GlobalProtect Internal Host Detection with Always-On and Enforcement</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1223648#M6572</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am trying to deploy GlobalProtect on some of our endpoints, but I'm running into a set of issues due to our business requirements.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The requirements are:&lt;BR /&gt;VPN is in Always-On with full enforcement&lt;BR /&gt;All traffic from those devices must stay internal, or be tunneled over the VPN (excepting what's needed for tunnel establishment)&lt;BR /&gt;MFA is required to establish a VPN tunnel outside&lt;/P&gt;
&lt;P&gt;Our MFA utilizes RADIUS with OTP&lt;/P&gt;
&lt;P&gt;The devices that GlobalProtect is installed on can move between our internal LAN and external locations&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My solution was to create internal and external portals with the same FQDN that resolve differently depending if the device is internal or external.&amp;nbsp; For the internal portal, I am using the machine certificate to auth which triggers internal host detection successfully.&amp;nbsp; Externally everything works as desired with the MFA authentication prompt triggering on user login and the connection method is set to User-Logon(Always-On) both internally and externally.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue I am running into is internal host detection before a user logs in.&amp;nbsp; If they reboot and let the device sit, it is completely inaccessible which I am pretty sure is going to brick patching.&amp;nbsp; I have the internal network CIDRs in the Enforce GlobalProtect agent config, but that hasnt helped.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think the normal recommendation would be to enable pre-login on the internal portal, but I was also hoping to have Connect Before Logon configured to address some weird remote-only user corner cases.&amp;nbsp; As far as I can tell, when I register CBL, it does not allow for any pre-login configurations to apply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have a good recommendation to address idle-machines while they are internally connected?&amp;nbsp; I can't disable Enforcement when it's internally connected because the worry would be that a user takes the device home without first logging in, and now it's on their home wifi with unrestricted internet access.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 02:44:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1223648#M6572</guid>
      <dc:creator>gkevlin</dc:creator>
      <dc:date>2025-03-13T02:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Internal Host Detection with Always-On and Enforcement</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1223823#M6573</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/72303"&gt;@gkevlin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Pretty much all of your issues are solved with pre-login. What exactly is the issue that is preventing you from enabling it and wanting CBL for the remote-only users; that's the whole point of pre-login and that capability solves the rest of your issues. &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 22:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1223823#M6573</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-03-13T22:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Internal Host Detection with Always-On and Enforcement</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1223902#M6578</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;That's my plan unless I can think of something else.&amp;nbsp; I'm just a little frustrated that with the way an initial portal authentication is required before internal network detection will trigger.&amp;nbsp; It makes automated provisioning a little awkward as after it gets provisioned it requires a portal authentication before it will allow communications after GP client is installed.&amp;nbsp; It also necessitates a second, internal-only portal since I could not find a way to enable machine certificate only authentication for internal hosts while enforcing MFA auth for external hosts.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 17:05:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1223902#M6578</guid>
      <dc:creator>gkevlin</dc:creator>
      <dc:date>2025-03-14T17:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Internal Host Detection with Always-On and Enforcement</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1225716#M6639</link>
      <description>&lt;P&gt;From a TAC Case I recently had:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;according to our internal documentation, Internal Host Detection and Internal Gateways are not supported in On-Demand mode.&lt;BR /&gt;Upon analyzing the logs from yesterday, I noticed that when connecting to '&amp;lt;ourportal&amp;gt;, the connection method is set to 'pre-logon-then-on-demand', whereas connecting to '&amp;lt;another portal&amp;gt;' uses the 'Pre-logon' connection method. Additionally, the workaround portal '&amp;lt;internal&amp;gt;' also uses the 'Pre-logon' method.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;This behavior is by design: In a 'pre-logon-then-on-demand' connection method configuration, Internal Host Detection does not function during the On-Demand phase. Here's a brief explanation of the flow:&lt;BR /&gt;- When the user powers on the PC, a tunnel is established using the Pre-logon method and the user is identified as an internal user.&lt;BR /&gt;- Once the user switches to a different portal, the Pre-logon tunnel is terminated.&lt;BR /&gt;- When the user clicks “Connect” manually, an On-Demand connection is initiated.&lt;BR /&gt;- During this On-Demand connection, Internal Host Detection is not supported even if it is configured.&lt;BR /&gt;So if you need Internal Host Detection to work, you must configure the connection method as either Pre-logon or User-logon on the portal configuration.&lt;BR /&gt;Path: Network &amp;gt; Portals &amp;gt; Agent &amp;gt; App &amp;gt; Connect Method&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 13:08:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-internal-host-detection-with-always-on-and/m-p/1225716#M6639</guid>
      <dc:creator>cjthorse82</dc:creator>
      <dc:date>2025-04-04T13:08:06Z</dc:date>
    </item>
  </channel>
</rss>

