<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internal Host Detection in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590240#M804</link>
    <description>&lt;P&gt;In order to achieve this. You have to configure internal host detection as specified in the link below. You only need to configure the IP address and the hostname under internal host detection in order to serve the purpose of not connecting to globalprotect when internal to the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When the user attempts to log in, the app does a reverse DNS lookup of an internal host using the specified&amp;nbsp;&lt;/SPAN&gt;IP Address&lt;SPAN&gt;&amp;nbsp;to the specified&amp;nbsp;&lt;/SPAN&gt;Hostname.&amp;nbsp;&lt;LI-WRAPPER&gt;&lt;SPAN&gt;The host serves as a reference point that does not have to be reachable but reverse DNS lookup should be successful only when the endpoint is inside the enterprise network. If the app finds the host, the endpoint is inside the network and the app connects to an internal gateway, if configured, or the GlobalProtect app shows the connection status as internal. If the app fails to find the internal host, the endpoint is outside the network and the app establishes a tunnel to one of the external gateways.&lt;/SPAN&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jun 2024 17:23:59 GMT</pubDate>
    <dc:creator>domari</dc:creator>
    <dc:date>2024-06-24T17:23:59Z</dc:date>
    <item>
      <title>Internal Host Detection</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/589898#M795</link>
      <description>&lt;P&gt;How do I ensure that when global protect identifies that it is on the internal network, it does not connect?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2024 12:15:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/589898#M795</guid>
      <dc:creator>cylusaragao</dc:creator>
      <dc:date>2024-06-19T12:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/589949#M796</link>
      <description>&lt;P&gt;From PanGPS log if you see "NetworkDiscoverThread: network type is internal." That means it connected to internal network.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 05:47:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/589949#M796</guid>
      <dc:creator>KhaleelE</dc:creator>
      <dc:date>2024-06-20T05:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590000#M798</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304428"&gt;@cylusaragao&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you take a look at the GlobalProtect Panel, you will see the following if you are internal to the corporate network.&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_7d49822540ec64domari_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="internal gp.png" style="width: 274px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60443i833A735CEC4395FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="internal gp.png" alt="internal gp.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 14:50:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590000#M798</guid>
      <dc:creator>domari</dc:creator>
      <dc:date>2024-06-20T14:50:03Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590025#M799</link>
      <description>&lt;P&gt;I want it to not connect to the internal network&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 18:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590025#M799</guid>
      <dc:creator>cylusaragao</dc:creator>
      <dc:date>2024-06-20T18:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590026#M800</link>
      <description>&lt;P&gt;What is the behavior you intend GP to do when the user is internal to the network? Connect to globalprotect on an external gateway (prisma access or on-prem gateway) or to the internal corporate network?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 18:52:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590026#M800</guid>
      <dc:creator>domari</dc:creator>
      <dc:date>2024-06-20T18:52:56Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590028#M801</link>
      <description>&lt;P&gt;I hope it identifies it is on the internal network and does not connect&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 20:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590028#M801</guid>
      <dc:creator>cylusaragao</dc:creator>
      <dc:date>2024-06-20T20:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590240#M804</link>
      <description>&lt;P&gt;In order to achieve this. You have to configure internal host detection as specified in the link below. You only need to configure the IP address and the hostname under internal host detection in order to serve the purpose of not connecting to globalprotect when internal to the network.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When the user attempts to log in, the app does a reverse DNS lookup of an internal host using the specified&amp;nbsp;&lt;/SPAN&gt;IP Address&lt;SPAN&gt;&amp;nbsp;to the specified&amp;nbsp;&lt;/SPAN&gt;Hostname.&amp;nbsp;&lt;LI-WRAPPER&gt;&lt;SPAN&gt;The host serves as a reference point that does not have to be reachable but reverse DNS lookup should be successful only when the endpoint is inside the enterprise network. If the app finds the host, the endpoint is inside the network and the app connects to an internal gateway, if configured, or the GlobalProtect app shows the connection status as internal. If the app fails to find the internal host, the endpoint is outside the network and the app establishes a tunnel to one of the external gateways.&lt;/SPAN&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 17:23:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/internal-host-detection/m-p/590240#M804</guid>
      <dc:creator>domari</dc:creator>
      <dc:date>2024-06-24T17:23:59Z</dc:date>
    </item>
  </channel>
</rss>

