<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Internal Detection in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-internal-detection/m-p/1251142#M7331</link>
    <description>&lt;DIV&gt;
&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;We are experiencing an intermittent connectivity issue on our Corp Wi‑Fi, and I’m trying to determine whether this is related to GlobalProtect internal network detection.&lt;/P&gt;
&lt;H3&gt;Environment&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;GlobalProtect Always‑On&lt;/LI&gt;
&lt;LI&gt;No split tunnelling&lt;/LI&gt;
&lt;LI&gt;Internal Host Detection configured using the IP address and hostname of a Domain Controller&lt;/LI&gt;
&lt;LI&gt;Corp Wi‑Fi uses RADIUS authentication&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We previously had two Domain Controllers available for RADIUS authentication on the Corp Wi‑Fi. Due to earlier issues, we are now operating with only one DC, which is also the DC used for GlobalProtect internal host detection.&lt;/P&gt;
&lt;H3&gt;Issue description&lt;/H3&gt;
&lt;P&gt;Several computers intermittently fail to work properly when connected to Corp Wi‑Fi:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Wi‑Fi connection itself completes successfully&lt;/LI&gt;
&lt;LI&gt;The DNS server (DC) is reachable and responds to ping&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;ping 8.8.8.8&lt;/CODE&gt; works&lt;/LI&gt;
&lt;LI&gt;DNS resolution works (for example, &lt;CODE&gt;nslookup google.com&lt;/CODE&gt;)&lt;/LI&gt;
&lt;LI&gt;However, &lt;CODE&gt;ping google.com&lt;/CODE&gt; returns &lt;STRONG&gt;“General failure”&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;No corresponding traffic is seen on the firewall&lt;/LI&gt;
&lt;LI&gt;There is no visible attempt from the endpoint to establish a GlobalProtect connection&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When the issue occurs:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The &lt;STRONG&gt;GlobalProtect icon is grey and flashing&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;The client does not identify the network as internal&lt;/LI&gt;
&lt;LI&gt;No Internet access&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After some time (sometimes quickly, sometimes after a long delay), the issue resolves on its own:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GlobalProtect successfully detects the internal network&lt;/LI&gt;
&lt;LI&gt;The icon turns blue and shows &lt;EM&gt;“Connected – You are on the internal corporate network”&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Internet access works normally again&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Observation&lt;/H3&gt;
&lt;P&gt;The problem seems to occur only when GlobalProtect fails to perform internal network detection. Machines that immediately show the blue “internal” state on GlobalProtect work without any issues. Guest Wi‑Fi and wired LAN connections do not show this behavior.&lt;/P&gt;
&lt;H3&gt;Question&lt;/H3&gt;
&lt;P&gt;Could relying on a single Domain Controller for both:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Corp Wi‑Fi authentication (RADIUS / DNS), and&lt;/LI&gt;
&lt;LI&gt;GlobalProtect internal host detection&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;cause intermittent internal detection failures on Wi‑Fi?&lt;/P&gt;
&lt;P&gt;Has anyone seen similar behavior, and what would be the recommended way to make internal detection more reliable in this scenario?&lt;/P&gt;
&lt;P&gt;Thanks in advance for any insights.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Mar 2026 03:53:54 GMT</pubDate>
    <dc:creator>M.Marzin</dc:creator>
    <dc:date>2026-03-30T03:53:54Z</dc:date>
    <item>
      <title>Global Protect Internal Detection</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-internal-detection/m-p/1251142#M7331</link>
      <description>&lt;DIV&gt;
&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;We are experiencing an intermittent connectivity issue on our Corp Wi‑Fi, and I’m trying to determine whether this is related to GlobalProtect internal network detection.&lt;/P&gt;
&lt;H3&gt;Environment&lt;/H3&gt;
&lt;UL&gt;
&lt;LI&gt;GlobalProtect Always‑On&lt;/LI&gt;
&lt;LI&gt;No split tunnelling&lt;/LI&gt;
&lt;LI&gt;Internal Host Detection configured using the IP address and hostname of a Domain Controller&lt;/LI&gt;
&lt;LI&gt;Corp Wi‑Fi uses RADIUS authentication&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;We previously had two Domain Controllers available for RADIUS authentication on the Corp Wi‑Fi. Due to earlier issues, we are now operating with only one DC, which is also the DC used for GlobalProtect internal host detection.&lt;/P&gt;
&lt;H3&gt;Issue description&lt;/H3&gt;
&lt;P&gt;Several computers intermittently fail to work properly when connected to Corp Wi‑Fi:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The Wi‑Fi connection itself completes successfully&lt;/LI&gt;
&lt;LI&gt;The DNS server (DC) is reachable and responds to ping&lt;/LI&gt;
&lt;LI&gt;&lt;CODE&gt;ping 8.8.8.8&lt;/CODE&gt; works&lt;/LI&gt;
&lt;LI&gt;DNS resolution works (for example, &lt;CODE&gt;nslookup google.com&lt;/CODE&gt;)&lt;/LI&gt;
&lt;LI&gt;However, &lt;CODE&gt;ping google.com&lt;/CODE&gt; returns &lt;STRONG&gt;“General failure”&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;No corresponding traffic is seen on the firewall&lt;/LI&gt;
&lt;LI&gt;There is no visible attempt from the endpoint to establish a GlobalProtect connection&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;When the issue occurs:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The &lt;STRONG&gt;GlobalProtect icon is grey and flashing&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;The client does not identify the network as internal&lt;/LI&gt;
&lt;LI&gt;No Internet access&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;After some time (sometimes quickly, sometimes after a long delay), the issue resolves on its own:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;GlobalProtect successfully detects the internal network&lt;/LI&gt;
&lt;LI&gt;The icon turns blue and shows &lt;EM&gt;“Connected – You are on the internal corporate network”&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Internet access works normally again&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;Observation&lt;/H3&gt;
&lt;P&gt;The problem seems to occur only when GlobalProtect fails to perform internal network detection. Machines that immediately show the blue “internal” state on GlobalProtect work without any issues. Guest Wi‑Fi and wired LAN connections do not show this behavior.&lt;/P&gt;
&lt;H3&gt;Question&lt;/H3&gt;
&lt;P&gt;Could relying on a single Domain Controller for both:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Corp Wi‑Fi authentication (RADIUS / DNS), and&lt;/LI&gt;
&lt;LI&gt;GlobalProtect internal host detection&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;cause intermittent internal detection failures on Wi‑Fi?&lt;/P&gt;
&lt;P&gt;Has anyone seen similar behavior, and what would be the recommended way to make internal detection more reliable in this scenario?&lt;/P&gt;
&lt;P&gt;Thanks in advance for any insights.&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2026 03:53:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-internal-detection/m-p/1251142#M7331</guid>
      <dc:creator>M.Marzin</dc:creator>
      <dc:date>2026-03-30T03:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Internal Detection</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-internal-detection/m-p/1251441#M7337</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1108571435"&gt;@M.Marzin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is possible that the issue is related to internal host detection timing. If the same server is busy and slow to respond to PTR queries. Since your DC is handling multiple roles.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would honestly try changing your IHD entry from your DC to a more dedicated internal DNS record for GP detection. For example, you could create a record such as "gp-ihd.company.local" with a static IP and matching PTR record then use that IP and hostname in the portals IHD detection settings.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This would give you a cleaner and more reliable detection point without depending on a DC that is also handling the work of 2 DCs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2026 17:41:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-internal-detection/m-p/1251441#M7337</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-04-02T17:41:54Z</dc:date>
    </item>
  </channel>
</rss>

