<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Geo blocking after GP login in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/geo-blocking-after-gp-login/m-p/1248799#M7290</link>
    <description>&lt;P&gt;My customer wants to give access based on user group and geo location.&lt;BR /&gt;Once authenticated the source IP is from the GP-tunnel ip-pool.&lt;BR /&gt;Can we still determine the source country once the tunnel is setup, or do we need to make that determination, after authentication and before completing the tunnel setup?&lt;/P&gt;</description>
    <pubDate>Mon, 23 Feb 2026 18:23:27 GMT</pubDate>
    <dc:creator>CHKlomp</dc:creator>
    <dc:date>2026-02-23T18:23:27Z</dc:date>
    <item>
      <title>Geo blocking after GP login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/geo-blocking-after-gp-login/m-p/1248799#M7290</link>
      <description>&lt;P&gt;My customer wants to give access based on user group and geo location.&lt;BR /&gt;Once authenticated the source IP is from the GP-tunnel ip-pool.&lt;BR /&gt;Can we still determine the source country once the tunnel is setup, or do we need to make that determination, after authentication and before completing the tunnel setup?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 18:23:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/geo-blocking-after-gp-login/m-p/1248799#M7290</guid>
      <dc:creator>CHKlomp</dc:creator>
      <dc:date>2026-02-23T18:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Geo blocking after GP login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/geo-blocking-after-gp-login/m-p/1248800#M7291</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/48132"&gt;@CHKlomp&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;If I understand your question correctly, no the source location is not essentially 'passed through' once your connected to GlobalProtect. You would need to have dedicated subnets allocated for each geolocation that you're planning on allowing access from if you're trying to utilize that for criteria in what GlobalProtect clients can access depending on their geolocation.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 18:26:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/geo-blocking-after-gp-login/m-p/1248800#M7291</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-02-23T18:26:46Z</dc:date>
    </item>
    <item>
      <title>Re: Geo blocking after GP login</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/geo-blocking-after-gp-login/m-p/1248801#M7292</link>
      <description>&lt;P&gt;OK &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;, that's what I was thinking as well. I hoped I missed something to make selection easier.&lt;BR /&gt;As this will need some careful carving out of IP-pools.&lt;BR /&gt;Will let some others chime in, before I'll mark your answer as solution.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Feb 2026 18:47:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/geo-blocking-after-gp-login/m-p/1248801#M7292</guid>
      <dc:creator>CHKlomp</dc:creator>
      <dc:date>2026-02-23T18:47:07Z</dc:date>
    </item>
  </channel>
</rss>

