<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP - Connect with SSL Only in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594244#M118269</link>
    <description>&lt;P&gt;I found it and it's working. Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2024 14:31:54 GMT</pubDate>
    <dc:creator>thompso104</dc:creator>
    <dc:date>2024-08-07T14:31:54Z</dc:date>
    <item>
      <title>GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594130#M118240</link>
      <description>&lt;P&gt;I am running panorama 11.1.3 and using prisma access (Mobile_User_Template). I have read that there is a&amp;nbsp;&lt;SPAN&gt;Connect with &lt;/SPAN&gt;&lt;EM&gt;SSL Only option&lt;/EM&gt; but I can not find this. I'm looking in Portal-&amp;gt;Agent-&amp;gt;App.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What am I missing?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is every setting I have pasted directly from Panorama:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connect Method&lt;BR /&gt;Pre-logon (Always On)&lt;BR /&gt;GlobalProtect App Config Refresh Interval (hours)&lt;BR /&gt;24 [1 - 168]&lt;BR /&gt;Allow user to disconnect GlobalProtect App (Always-on mode)&lt;BR /&gt;Allow&lt;BR /&gt;Display the following reasons to disconnect GlobalProtect (Always-on mode)&lt;BR /&gt;Allow User to Uninstall GlobalProtect App (Windows Only)&lt;BR /&gt;Allow&lt;BR /&gt;Allow User to Upgrade GlobalProtect App&lt;BR /&gt;Allow with Prompt&lt;BR /&gt;Allow user to Sign Out from GlobalProtect App&lt;BR /&gt;Yes&lt;BR /&gt;Allow user to extend GlobalProtect User Session&lt;BR /&gt;No&lt;BR /&gt;Use Single Sign-on (Windows)&lt;BR /&gt;No&lt;BR /&gt;Use Single Sign-on for Smart card PIN (Windows)&lt;BR /&gt;No&lt;BR /&gt;Use Single Sign-on (macOS)&lt;BR /&gt;No&lt;BR /&gt;Clear Single Sign-On Credentials on Logout (Windows Only)&lt;BR /&gt;Yes&lt;BR /&gt;Use Default Authentication on Kerberos Authentication Failure&lt;BR /&gt;Yes&lt;BR /&gt;Use Default Browser for SAML Authentication&lt;BR /&gt;No&lt;BR /&gt;Automatic Restoration of VPN Connection Timeout (min)&lt;BR /&gt;30 [0 - 180]&lt;BR /&gt;Wait Time Between VPN Connection Restore Attempts (sec)&lt;BR /&gt;5 [1 - 60]&lt;BR /&gt;Endpoint Traffic Policy Enforcement&lt;BR /&gt;No&lt;BR /&gt;Enforce GlobalProtect Connection for Network Access&lt;BR /&gt;No&lt;BR /&gt;Allow traffic to specified hosts/networks when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established&lt;BR /&gt;&lt;BR /&gt;Allow traffic to specified fqdn when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established&lt;BR /&gt;&lt;BR /&gt;Captive Portal Exception Timeout (sec)&lt;BR /&gt;0 [0 - 3600]&lt;BR /&gt;Automatically Launch Webpage in Default Browser Upon Captive Portal Detection&lt;BR /&gt;Traffic Blocking Notification Delay (sec)&lt;BR /&gt;15 [5 - 120]&lt;BR /&gt;Display Traffic Blocking Notification Message&lt;BR /&gt;Yes&lt;BR /&gt;Traffic Blocking Notification Message&lt;BR /&gt;&amp;lt;div style="font-family:'Helvetica Neue';"&amp;gt;&amp;lt;h1 style="color:red;text-align:center; margin: 0; font-size: 30px;"&amp;gt;Notice&amp;lt;/h1&amp;gt;&amp;lt;p style="margin: 0;font-size: 15px; line-height: 1.2em;"&amp;gt;To access the network, you must first connect to GlobalProtect.&amp;lt;/p&amp;gt;&amp;lt;/div&amp;gt;&lt;BR /&gt;Allow User to Dismiss Traffic Blocking Notifications&lt;BR /&gt;Yes&lt;BR /&gt;Display Captive Portal Detection Message&lt;BR /&gt;No&lt;BR /&gt;Captive Portal Detection Message&lt;BR /&gt;&amp;lt;div style="font-family:'Helvetica Neue';"&amp;gt;&amp;lt;h1 style="color:red;text-align:center; margin: 0; font-size: 30px;"&amp;gt;Captive Portal Detected&amp;lt;/h1&amp;gt;&amp;lt;p style="margin: 0; font-size: 15px; line-height: 1.2em;"&amp;gt;GlobalProtect has temporarily permitted network access for you to connect to the Internet. Follow instructions from your internet provider.&amp;lt;/p&amp;gt;&amp;lt;p style="margin: 0; font-size: 15px; line-height: 1.2em;"&amp;gt;If you let the connection time out, open GlobalProtect and click Connect to try again.&amp;lt;/p&amp;gt;&amp;lt;/div&amp;gt;&lt;BR /&gt;Captive Portal Notification Delay (sec)&lt;BR /&gt;5 [1 - 120]&lt;BR /&gt;Client Certificate Store Lookup&lt;BR /&gt;User and Machine&lt;BR /&gt;SCEP Certificate Renewal Period (days)&lt;BR /&gt;7 [0 - 30]&lt;BR /&gt;Extended Key Usage OID for Client Certificate&lt;BR /&gt;Retain Connection on Smart Card Removal (Windows Only)&lt;BR /&gt;Yes&lt;BR /&gt;Enable Advanced View&lt;BR /&gt;Yes&lt;BR /&gt;Allow User to Dismiss Welcome Page&lt;BR /&gt;Yes&lt;BR /&gt;Have User Accept Terms Of Use before Creating Tunnel&lt;BR /&gt;No&lt;BR /&gt;Enable Rediscover Network Option&lt;BR /&gt;Yes&lt;BR /&gt;Enable Resubmit Host Profile Option&lt;BR /&gt;Yes&lt;BR /&gt;Enable Intelligent Portal Selection&lt;BR /&gt;No&lt;BR /&gt;Allow User to Change Portal Address&lt;BR /&gt;Yes&lt;BR /&gt;Allow User to Continue with Invalid Portal Server Certificate&lt;BR /&gt;No&lt;BR /&gt;Display GlobalProtect Icon&lt;BR /&gt;Yes&lt;BR /&gt;User Switch Tunnel Rename Timeout (sec)&lt;BR /&gt;0 [0 - 7200]&lt;BR /&gt;Pre-Logon Tunnel Rename Timeout (sec) (Windows Only)&lt;BR /&gt;-1 [-1 - 7200]&lt;BR /&gt;Preserve Tunnel on User Logoff Timeout (sec)&lt;BR /&gt;0 [0 - 600]&lt;BR /&gt;Custom Password Expiration Message (LDAP Authentication Only)&lt;BR /&gt;Automatically Use SSL When IPSec Is Unreliable (hours)&lt;BR /&gt;0 [0 - 168]&lt;BR /&gt;Display IPSec to SSL Fallback Notification&lt;BR /&gt;Yes&lt;BR /&gt;Advanced Control for Tunnel Mode Behavior&lt;BR /&gt;No&lt;BR /&gt;GlobalProtect Connection MTU (bytes)&lt;BR /&gt;1300&lt;BR /&gt;Maximum Internal Gateway Connection Attempts&lt;BR /&gt;0 [0 - 100]&lt;BR /&gt;Enable Advanced Internal Host Detection&lt;BR /&gt;No&lt;BR /&gt;Portal Connection Timeout (sec)&lt;BR /&gt;5 [1 - 600]&lt;BR /&gt;TCP Connection Timeout (sec)&lt;BR /&gt;5 [1 - 600]&lt;BR /&gt;TCP Receive Timeout (sec)&lt;BR /&gt;30 [1 - 600]&lt;BR /&gt;Split-Tunnel Option&lt;BR /&gt;Both Network Traffic and DNS&lt;BR /&gt;Enhanced Split-Tunnel Client Certificate Public Key&lt;BR /&gt;Empty&lt;BR /&gt;Resolve All FQDNs Using DNS Servers Assigned by the Tunnel (Windows Only)&lt;BR /&gt;Yes&lt;BR /&gt;Append Local Search Domains to Tunnel DNS Suffixes (Mac Only)&lt;BR /&gt;No&lt;BR /&gt;Update DNS Settings at Connect (Windows Only) (Deprecated)&lt;BR /&gt;No&lt;BR /&gt;Local Proxy Port&lt;BR /&gt;9999 [1024 - 65534]&lt;BR /&gt;Agent Mode for Prisma Access&lt;BR /&gt;Tunnel&lt;BR /&gt;Proxy Auto-Configuration (PAC) File URL&lt;BR /&gt;Detect Proxy for Each Connection (Windows only)&lt;BR /&gt;No&lt;BR /&gt;Set Up Tunnel Over Proxy (Windows &amp;amp; Mac Only)&lt;BR /&gt;Yes&lt;BR /&gt;HIP Process Remediation Timeout (sec)&lt;BR /&gt;0 [0 - 300]&lt;BR /&gt;HIP Process Remediation Retry&lt;BR /&gt;0 [0 - 3]&lt;BR /&gt;HIP Process Remediation integrity Check&lt;BR /&gt;Send HIP Report Immediately if Windows Security Center (WSC) State Changes (Windows Only)&lt;BR /&gt;Yes&lt;BR /&gt;Enable Inbound Authentication Prompts from MFA Gateways&lt;BR /&gt;No&lt;BR /&gt;Network Port for Inbound Authentication Prompts (UDP)&lt;BR /&gt;4501 [1 - 65535]&lt;BR /&gt;Trusted MFA Gateways&lt;BR /&gt;&lt;BR /&gt;Inbound Authentication Message&lt;BR /&gt;You have attempted to access a protected resource that requires additional authentication. Proceed to authenticate at&lt;BR /&gt;Suppress Multiple Inbound MFA Prompts (sec)&lt;BR /&gt;0 [0 - 180]&lt;BR /&gt;IPv6 Preferred&lt;BR /&gt;No&lt;BR /&gt;Change Password Message&lt;BR /&gt;Log Gateway Selection Criteria&lt;BR /&gt;No&lt;BR /&gt;Enable Autonomous DEM and GlobalProtect App Log Collection for Troubleshooting&lt;BR /&gt;Yes&lt;BR /&gt;Display Autonomous DEM Updates Notification&lt;BR /&gt;No&lt;BR /&gt;Run Diagnostics Tests for These Destination Web Servers&lt;BR /&gt;&lt;BR /&gt;Autonomous DEM endpoint agent for Prisma Access for GP version 6.2 and below (Windows &amp;amp; MAC only)&lt;BR /&gt;Install and user can enable/disable agent from GlobalProtect&lt;BR /&gt;Access Experience (ADEM, App Acceleration, End user coaching) for GP 6.3 and above (Windows &amp;amp; MAC only)&lt;BR /&gt;No Action (The Agent state remains as is)&lt;BR /&gt;Device Added to Quarantine Message&lt;BR /&gt;Your security policy has restricted access to the network from this device. If the issue persists, contact your administrator.&lt;BR /&gt;Device Removed from Quarantine Message&lt;BR /&gt;Your security policy has restored access to the network from this device. If you still cannot access the network, contact your administrator.&lt;BR /&gt;Display Status Panel at Startup (Windows Only)&lt;BR /&gt;No&lt;BR /&gt;Allow GlobalProtect UI to Persist for User Input&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 13:24:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594130#M118240</guid>
      <dc:creator>thompso104</dc:creator>
      <dc:date>2024-08-06T13:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594149#M118243</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you managing prisma via Panorama? You can disable IPSec under the GP Gateway. What are you looking to disable IPsec for as IPsec is more secure and more efficient than SSL.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Claw4609_0-1722956272010.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61359i8AA747C5673C22B4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Claw4609_0-1722956272010.png" alt="Claw4609_0-1722956272010.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 14:58:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594149#M118243</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-08-06T14:58:30Z</dc:date>
    </item>
    <item>
      <title>Re: GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594169#M118248</link>
      <description>&lt;P&gt;Yes managing prisma access with panorama. I want to make an agent profile for users that have frequent disconnects and give them a lower MTU. I was asked by TAC at one point to enable the SSL Only option but I can't find it.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 16:31:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594169#M118248</guid>
      <dc:creator>thompso104</dc:creator>
      <dc:date>2024-08-06T16:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594229#M118262</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173922"&gt;@thompso104&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Yes managing prisma access with panorama. I want to make an agent profile for users that have frequent disconnects and give them a lower MTU. I was asked by TAC at one point to enable the SSL Only option but I can't find it.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/173922"&gt;@thompso104&lt;/a&gt;&amp;nbsp;The screenshot that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;shared with you above will accomplish what you're saying you want to do.&amp;nbsp; By having the "Enable IPsec" box unchecked GP VPN connections will only be established via SSL.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:01:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594229#M118262</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-08-07T13:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594232#M118263</link>
      <description>&lt;P&gt;That would affect every user at the gateway. My requirement is per user at the portal or app level just like how MTU is set. It's explained in this doc. Sounds like this doc should be updated since the setting is no longer an option and it can only be done per gateway. &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/customize-the-globalprotect-app" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-portals/customize-the-globalprotect-app&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-08-07 at 9.26.09 AM.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61370iC2500C3FB0C0E67F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-08-07 at 9.26.09 AM.png" alt="Screenshot 2024-08-07 at 9.26.09 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:27:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594232#M118263</guid>
      <dc:creator>thompso104</dc:creator>
      <dc:date>2024-08-07T13:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594234#M118264</link>
      <description>&lt;P&gt;Which version are you using? Its looks like that setting was renamed to "Advanced Control for Tunnel Mode Behavior"&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:37:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594234#M118264</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-08-07T13:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594237#M118267</link>
      <description>&lt;P&gt;Yeah then it looks like you should be looking for&amp;nbsp;&lt;SPAN&gt;Advanced Control for Tunnel Mode Behavior and then under that, selecting ssl only.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/customize-the-globalprotect-app" target="_blank"&gt;Customize the GlobalProtect App (paloaltonetworks.com)&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 13:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594237#M118267</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2024-08-07T13:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: GP - Connect with SSL Only</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594244#M118269</link>
      <description>&lt;P&gt;I found it and it's working. Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/227075"&gt;@Claw4609&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2024 14:31:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-connect-with-ssl-only/m-p/594244#M118269</guid>
      <dc:creator>thompso104</dc:creator>
      <dc:date>2024-08-07T14:31:54Z</dc:date>
    </item>
  </channel>
</rss>

