<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Endpoint Traffic Policy Enforcement on Prisma Access in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/endpoint-traffic-policy-enforcement-on-prisma-access/m-p/1261428#M7484</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying out the "Endpoint Traffic Policy Enforcement" feature on GP to enforce users who are actively trying to avoid connecting to VPN (even if this is set to connect automatically).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have set this setting to "All traffic" on a small test group and it was working great. However, one of the users tried to connect to a Windows 11 VM remotely, and that had blocked everyone out of the machine. The VM is located on the internal network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot find anywhere in the Portal configuration where I can set an exception on a machine level; is there a way to allow inbound ICMP/RDP from machines on the internal network?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-portals/endpoint-traffic-policy-enforcement" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-portals/endpoint-traffic-policy-enforcement&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2026 09:10:43 GMT</pubDate>
    <dc:creator>N.Nicolaides</dc:creator>
    <dc:date>2026-08-10T09:10:43Z</dc:date>
    <item>
      <title>Endpoint Traffic Policy Enforcement on Prisma Access</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/endpoint-traffic-policy-enforcement-on-prisma-access/m-p/1261428#M7484</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying out the "Endpoint Traffic Policy Enforcement" feature on GP to enforce users who are actively trying to avoid connecting to VPN (even if this is set to connect automatically).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have set this setting to "All traffic" on a small test group and it was working great. However, one of the users tried to connect to a Windows 11 VM remotely, and that had blocked everyone out of the machine. The VM is located on the internal network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cannot find anywhere in the Portal configuration where I can set an exception on a machine level; is there a way to allow inbound ICMP/RDP from machines on the internal network?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-portals/endpoint-traffic-policy-enforcement" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/administration/globalprotect-portals/endpoint-traffic-policy-enforcement&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2026 09:10:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/endpoint-traffic-policy-enforcement-on-prisma-access/m-p/1261428#M7484</guid>
      <dc:creator>N.Nicolaides</dc:creator>
      <dc:date>2026-08-10T09:10:43Z</dc:date>
    </item>
  </channel>
</rss>

