<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Looking for documentation on how to set up an internal GP gateway for User-ID in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/looking-for-documentation-on-how-to-set-up-an-internal-gp/m-p/1256741#M7417</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108539"&gt;@inSync-MarkValpreda&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;You typically do not need a separate portal. The existing portal can provide the GP client config, including internal host detection and the internal gateway. The internal gateway can be on an internal interface or loopback, as long as the FQDN resolves internally to that firewall IP and the gateway certificate matches the name users connect to.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;To make this seamless, configure the GP app for &lt;/SPAN&gt;&lt;STRONG&gt;User-Logon / Always On&lt;/STRONG&gt;&lt;SPAN&gt; so the client can automatically detect whether it is internal or external and connect accordingly. For User-ID only, the internal gateway can be configured without tunneling user traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would recommend reviewing these docs first:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/globalprotect-for-internal-hip-checking-and-user-based-access" target="_self"&gt;&lt;SPAN&gt;GlobalProtect for Internal HIP Checking and User-Based Access&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.packetswitch.co.uk/global-protect-internal-host-detection-internal-gateways-lessons-learnt/" target="_self"&gt;&lt;SPAN&gt;Global Protect Internal Host Detection &amp;amp; Internal Gateways - Packetswitch&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps! and please let us know how it goes or if anything comes up.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Jun 2026 18:30:59 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-06-18T18:30:59Z</dc:date>
    <item>
      <title>Looking for documentation on how to set up an internal GP gateway for User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/looking-for-documentation-on-how-to-set-up-an-internal-gp/m-p/1256616#M7416</link>
      <description>&lt;P&gt;This is a PA environment I have inherited and I don't have a PA background, most everything was already set up....I just maintain security rules, NAT, etc....basic stuff.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Been having quite a time with our Macs and User-ID through Active Directory and using the App-ID Agent on a server. After a few cases and frustrated users, think we need to pivot to an internal GP gateway for user ID.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't know if I should take my existing GP portal that is set on a loopback address to include internal detection, or set up a new one with my LAN interface? Do I need to set my GP DNS name internally to point to an IP on my PA-1410? How do I make this seamless to the users so they don't have to log into GP client on their machine?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In looking at some links on here as well as through other searches, I didn't find anything that really jumped out at me that matches what we are trying to accomplish. I'm hoping that someone can nudge me in the right direction.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 01:58:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/looking-for-documentation-on-how-to-set-up-an-internal-gp/m-p/1256616#M7416</guid>
      <dc:creator>inSync-MarkValpreda</dc:creator>
      <dc:date>2026-06-18T01:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for documentation on how to set up an internal GP gateway for User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/looking-for-documentation-on-how-to-set-up-an-internal-gp/m-p/1256741#M7417</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/108539"&gt;@inSync-MarkValpreda&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;You typically do not need a separate portal. The existing portal can provide the GP client config, including internal host detection and the internal gateway. The internal gateway can be on an internal interface or loopback, as long as the FQDN resolves internally to that firewall IP and the gateway certificate matches the name users connect to.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;To make this seamless, configure the GP app for &lt;/SPAN&gt;&lt;STRONG&gt;User-Logon / Always On&lt;/STRONG&gt;&lt;SPAN&gt; so the client can automatically detect whether it is internal or external and connect accordingly. For User-ID only, the internal gateway can be configured without tunneling user traffic.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would recommend reviewing these docs first:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-quick-configs/globalprotect-for-internal-hip-checking-and-user-based-access" target="_self"&gt;&lt;SPAN&gt;GlobalProtect for Internal HIP Checking and User-Based Access&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.packetswitch.co.uk/global-protect-internal-host-detection-internal-gateways-lessons-learnt/" target="_self"&gt;&lt;SPAN&gt;Global Protect Internal Host Detection &amp;amp; Internal Gateways - Packetswitch&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this helps! and please let us know how it goes or if anything comes up.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jun 2026 18:30:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/looking-for-documentation-on-how-to-set-up-an-internal-gp/m-p/1256741#M7417</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-06-18T18:30:59Z</dc:date>
    </item>
  </channel>
</rss>

