<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic #Global Protect enabling Always on in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-enabling-always-on/m-p/1226204#M6670</link>
    <description>&lt;P&gt;Hi Team , I am planning to implement&amp;nbsp;Always on Global protect client 6.0 , so would like to know the best practices in implementations and how can i plan the implementation phase ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR data-start="2447" data-end="2630"&gt;
&lt;TD class="" data-start="2447" data-end="2482"&gt;&lt;STRONG data-start="2449" data-end="2475"&gt;User-logon (Always On)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD class="" data-start="2482" data-end="2560"&gt;Most standard corporate users&lt;/TD&gt;
&lt;TD class="min-w-[calc(var(--thread-content-max-width)/3)]" data-start="2560" data-end="2630"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR data-start="2631" data-end="2813"&gt;
&lt;TD class="" data-start="2631" data-end="2666"&gt;&lt;STRONG data-start="2633" data-end="2658"&gt;Pre-logon (Always On)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD class="min-w-[calc(var(--thread-content-max-width)/3)]" data-start="2666" data-end="2744"&gt;Domain-joined laptops needing remote AD login, GPOs, scripts&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it advisable to configure internal gateway for the internal users , now the current setup is&amp;nbsp; internal host detection &amp;gt;&amp;gt; No tunnel.&lt;/P&gt;
&lt;P&gt;Please share best practices in Agent App for always on .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks KK&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Apr 2025 11:07:03 GMT</pubDate>
    <dc:creator>k.pillai</dc:creator>
    <dc:date>2025-04-10T11:07:03Z</dc:date>
    <item>
      <title>#Global Protect enabling Always on</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-enabling-always-on/m-p/1226204#M6670</link>
      <description>&lt;P&gt;Hi Team , I am planning to implement&amp;nbsp;Always on Global protect client 6.0 , so would like to know the best practices in implementations and how can i plan the implementation phase ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR data-start="2447" data-end="2630"&gt;
&lt;TD class="" data-start="2447" data-end="2482"&gt;&lt;STRONG data-start="2449" data-end="2475"&gt;User-logon (Always On)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD class="" data-start="2482" data-end="2560"&gt;Most standard corporate users&lt;/TD&gt;
&lt;TD class="min-w-[calc(var(--thread-content-max-width)/3)]" data-start="2560" data-end="2630"&gt;&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR data-start="2631" data-end="2813"&gt;
&lt;TD class="" data-start="2631" data-end="2666"&gt;&lt;STRONG data-start="2633" data-end="2658"&gt;Pre-logon (Always On)&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD class="min-w-[calc(var(--thread-content-max-width)/3)]" data-start="2666" data-end="2744"&gt;Domain-joined laptops needing remote AD login, GPOs, scripts&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is it advisable to configure internal gateway for the internal users , now the current setup is&amp;nbsp; internal host detection &amp;gt;&amp;gt; No tunnel.&lt;/P&gt;
&lt;P&gt;Please share best practices in Agent App for always on .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks KK&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 11:07:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-enabling-always-on/m-p/1226204#M6670</guid>
      <dc:creator>k.pillai</dc:creator>
      <dc:date>2025-04-10T11:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: #Global Protect enabling Always on</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-enabling-always-on/m-p/1226792#M6695</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1485311473"&gt;@k.pillai&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As far as deciding on an internal gateway, it really depends on your goals and current visibility for internal users. I would think about a few things:&lt;BR /&gt;&lt;BR /&gt;Is there east-west visibility within the internal network (does internal traffic traverse your firewall/firewalls today?)&lt;/P&gt;
&lt;P&gt;What type of applications or services do internal users access? Is any of that considered sensitive?&lt;BR /&gt;Are there any security tools currently leveraged within the environment?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any compliance requirements?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If internal traffic isn't inspected today or if monitoring and threat prevention capabilities are important, then an internal gateway with always-on vpn can definitely be valuable.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 05:28:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-enabling-always-on/m-p/1226792#M6695</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2025-04-17T05:28:13Z</dc:date>
    </item>
  </channel>
</rss>

