<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prisma Access Internal Gateway in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/prisma-access-internal-gateway/m-p/1225809#M6647</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300092"&gt;@AhmedAlRashed&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you Panorama or SCM Managed ?&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="68" data-end="192"&gt;You said it didn't work or it's just the mapping. Were you able to connect and did IHD (Internal Host Detection) succeed?&lt;/P&gt;
&lt;P class="" data-start="194" data-end="287"&gt;On your GlobalProtect, do you see the message: &lt;EM data-start="241" data-end="286"&gt;"You are on the Internal Corporate Network"&amp;nbsp;&lt;/EM&gt;?&lt;/P&gt;
&lt;P class="" data-start="194" data-end="287"&gt;What's your GP client version et Prisma Access version (Plugin/dataplane) ?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Apr 2025 08:18:58 GMT</pubDate>
    <dc:creator>ClementADNOV</dc:creator>
    <dc:date>2025-04-07T08:18:58Z</dc:date>
    <item>
      <title>Prisma Access Internal Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/prisma-access-internal-gateway/m-p/1225664#M6637</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone had used Prisma Access Internal Gateway for user-to-IP mapping from Remote Networks to Prisma Access?&lt;/P&gt;
&lt;P&gt;It doesn't work for me!&lt;/P&gt;
&lt;P&gt;I can view the source user under GlobalProtect Logs/Strata Logging Service but not under traffic logs&lt;/P&gt;
&lt;P&gt;The connection method is always on.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hopefully someone out there has configured it and it is working for them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 03:20:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/prisma-access-internal-gateway/m-p/1225664#M6637</guid>
      <dc:creator>AhmedAlRashed</dc:creator>
      <dc:date>2025-04-04T03:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Internal Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/prisma-access-internal-gateway/m-p/1225809#M6647</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/300092"&gt;@AhmedAlRashed&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you Panorama or SCM Managed ?&amp;nbsp;&lt;/P&gt;
&lt;P class="" data-start="68" data-end="192"&gt;You said it didn't work or it's just the mapping. Were you able to connect and did IHD (Internal Host Detection) succeed?&lt;/P&gt;
&lt;P class="" data-start="194" data-end="287"&gt;On your GlobalProtect, do you see the message: &lt;EM data-start="241" data-end="286"&gt;"You are on the Internal Corporate Network"&amp;nbsp;&lt;/EM&gt;?&lt;/P&gt;
&lt;P class="" data-start="194" data-end="287"&gt;What's your GP client version et Prisma Access version (Plugin/dataplane) ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 08:18:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/prisma-access-internal-gateway/m-p/1225809#M6647</guid>
      <dc:creator>ClementADNOV</dc:creator>
      <dc:date>2025-04-07T08:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access Internal Gateway</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/prisma-access-internal-gateway/m-p/1225871#M6651</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/324729"&gt;@ClementADNOV&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It’s SCM-managed.&lt;/P&gt;
&lt;P&gt;Initially I tried using our own internal DNS server to set up IHD. The GlobalProtect client didn’t establish the tunnel - it just showed “You are on the Internal Corporate Network”.&lt;/P&gt;
&lt;P&gt;I checked the PanGPS logs and it looks like the client isn’t able to reach any-igw.gpojgsy2ony.gw.gpcloudservice.com:443.&lt;/P&gt;
&lt;P&gt;I then enabled Remote Network IHD and set up the laptop to use the Prisma Access DNS proxy - and that worked. I could see the source users in the traffic logs.&lt;/P&gt;
&lt;P&gt;TAC have advised that we need to use the Prisma Access DNS proxy for IHD to work, and it doesn’t support using our internal DNS for the client to perform the IHD check.&lt;/P&gt;
&lt;P&gt;Bit odd really, as the documentation doesn’t mention that the Prisma Access DNS proxy is a requirement&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-advanced-deployments/prisma-access-remote-network-advanced-deployments/prisma-access-internal-gateway" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-advanced-deployments/prisma-access-remote-network-advanced-deployments/prisma-access-internal-gateway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;(P5036-T8420)Debug( 930): 04/04/25 18:31:03:733 SSL connecting to any-igw.gpojgsy2ony.gw.gpcloudservice.com&lt;BR /&gt;(P5036-T8420)Debug( 316): 04/04/25 18:31:03:733 host is FQDN: any-igw.gpojgsy2ony.gw.gpcloudservice.com&lt;BR /&gt;(P5036-T8420)Error( 856): 04/04/25 18:31:03:733 getaddrinfo for fqdn any-igw.gpojgsy2ony.gw.gpcloudservice.com failed, 0.&lt;BR /&gt;(P5036-T8420)Debug( 567): 04/04/25 18:31:03:733 getaddrinfo of any-igw.gpojgsy2ony.gw.gpcloudservice.com failed with error 11001, No such host is known. &lt;BR /&gt;(P5036-T8420)Debug( 935): 04/04/25 18:31:03:733 do_tcp_connect() failed&lt;BR /&gt;(P5036-T8420)Error(6795): 04/04/25 18:31:03:733 Failed to ssl connect to 'any-igw.gpojgsy2ony.gw.gpcloudservice.com:443', Disconect ssl and returns FALSE.&lt;BR /&gt;(P5036-T8420)Debug(6823): 04/04/25 18:31:03:733 Already tried both ipv4 and ipv6 for gateway any-igw.gpojgsy2ony.gw.gpcloudservice.com&lt;BR /&gt;(P5036-T8420)Debug(6030): 04/04/25 18:31:03:733 Show Gateway Prisma Access Internal Gateway: The network connection is unreachable or the gateway is unresponsive. Check the network connection and reconnect.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 22:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/prisma-access-internal-gateway/m-p/1225871#M6651</guid>
      <dc:creator>AhmedAlRashed</dc:creator>
      <dc:date>2025-04-07T22:58:43Z</dc:date>
    </item>
  </channel>
</rss>

