<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enforcing Global Protect only on remote sessions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532210#M109726</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I believe you would either need to setup an install portal/gateway or the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PNid" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PNid&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Fri, 24 Feb 2023 18:05:51 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2023-02-24T18:05:51Z</dc:date>
    <item>
      <title>Enforcing Global Protect only on remote sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532182#M109717</link>
      <description>&lt;P&gt;My company only allows company issued laptops (Windows only) to remotely connect to our network via VPN. Since these are company devices I feel they should always be restricted to company internet usage polices that only allow access to approved sites and categories. My users are all in office based but do need to remote in for those few work at home days (weather, kid issues, blah blah) or if they are on the road.&amp;nbsp; Out of my 120 devices, only 15 of them even use VPN now so small group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are only 2 months into using PA and I have Global Protect configure and working for single tunnel access, AD authentication, with the GP Portal set to user log in (always on). Portal and gateway are on the same device and pointed to the external interface. We do not have HIP licensing or requirements (yet).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been playing with the Enforce Global Protect option. I discovered that if I turn that option on I can not log in when I am in the office. I wasn't surprised by this result, and I am having issues finding any documentation on what the correct config is for this scenario and wanted to make sure I wasn't missing some easy setting or config change.&lt;/P&gt;
&lt;P&gt;What it looks like I have to do is create a 2nd gateway attached to the internal interface if I want the Enforce option on. Is that correct or is there a setting or something I can make?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 14:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532182#M109717</guid>
      <dc:creator>dahoove</dc:creator>
      <dc:date>2023-02-24T14:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing Global Protect only on remote sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532210#M109726</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I believe you would either need to setup an install portal/gateway or the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PNid" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PNid&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 18:05:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532210#M109726</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-02-24T18:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing Global Protect only on remote sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532225#M109734</link>
      <description>&lt;P&gt;That might be needed but didn't fix the issue. I creates an internal gateway went into portal config under internal and add the internal info to that. When I try to connect the GP client from an internal network it seems to see the portal and then tries to get a configuration but then throws a Network connection is unreachable or portal is unresponsive.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 19:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532225#M109734</guid>
      <dc:creator>dahoove</dc:creator>
      <dc:date>2023-02-24T19:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: Enforcing Global Protect only on remote sessions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532229#M109736</link>
      <description>&lt;P&gt;If its using an external IP/interface, you might need a u-turn NAT and policies to accomplish.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllzCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CllzCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 19:42:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/enforcing-global-protect-only-on-remote-sessions/m-p/532229#M109736</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2023-02-24T19:42:23Z</dc:date>
    </item>
  </channel>
</rss>

