<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forced VPN Connection with GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/1221899#M123394</link>
    <description>&lt;P&gt;Yes, it is possible. Here is the link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/enforce-globalprotect-for-network-access" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/enforce-globalprotect-for-network-access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR, Peter&lt;/P&gt;</description>
    <pubDate>Tue, 25 Feb 2025 10:36:06 GMT</pubDate>
    <dc:creator>segap</dc:creator>
    <dc:date>2025-02-25T10:36:06Z</dc:date>
    <item>
      <title>Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21167#M15461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to force a VPN Connection so the client can only use wifi or ethernet if he is in the office or has a active VPN Connection?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 12:34:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21167#M15461</guid>
      <dc:creator>gsteiner</dc:creator>
      <dc:date>2013-08-05T12:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21168#M15462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's base on the gateway lookup resolution and you have to configure an internal gateway to do that.&lt;/P&gt;&lt;P&gt;and if the client is connected to the internal gateway no ipsec or vpn tunnel is mounted but you can use HIP information or login information to create your secuty rule that limit the accessible ressource for this device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3930"&gt;https://live.paloaltonetworks.com/docs/DOC-3930&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 12:42:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21168#M15462</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-08-05T12:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21169#M15463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning, &lt;/P&gt;&lt;P&gt;If you are talking about a user who wants to connect to an internal gateway, we can configure the PANFW gateway on a VPN tunnel with in the office as well. By default the PANFW supports the SSL connection to the GP users ( whether connected internally or externally), and we have to manually configure the gateways to accept a&amp;nbsp; VPN connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find the information on the below thread:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/message/29549#29549"&gt;https://live.paloaltonetworks.com/message/29549#29549&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps,&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 12:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21169#M15463</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-05T12:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21170#M15464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Really important for my customer is that the client can never connect directly to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry if I have to ask it again for my understanding, but that is absolutly important, else i need to buy a other vpn solution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 13:14:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21170#M15464</guid>
      <dc:creator>gsteiner</dc:creator>
      <dc:date>2013-08-05T13:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21171#M15465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you elaborate more upon the requirement. Your question isn't very&amp;nbsp; clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 13:35:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21171#M15465</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-05T13:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21172#M15466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Requirement from the Customer say that the Laptop are not allowed to be exposed to the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon the Laptop is connected to a network it has to establish a vpn or disable the connection.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 14:00:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21172#M15466</guid>
      <dc:creator>gsteiner</dc:creator>
      <dc:date>2013-08-05T14:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21173#M15467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can leverage the single sign on feature, so when the laptop having the agent on it, connects within the network and has been&amp;nbsp; successfully authenticated, a VPN tunnel gets established and he can go out to the internet via the tunnel. If he fails to get authenticated, the user will get identified as an unknown user, and we can configure a rule to block all unknown users. That way he cannot get access to the internet, although he is connected internally in the network. Like Gregoux mentioned as well, you can use the hip checks to deny access to the machines if they do not match a config criteria.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Aug 2013 14:50:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21173#M15467</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-05T14:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21174#M15468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can create split tunnel by configuring access routes in the global protect gateway.&lt;/P&gt;&lt;P&gt;This way with security policy you can only allow access to ip address that you want and block access to the rest with the security policy.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 06:11:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21174#M15468</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-06T06:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21175#M15469</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where can I configure a rule on the client side that if he is a unknows user traffic is blocked? On the Firewall of course...but on the laptop??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At home there is no PA to configure such things.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Aug 2013 06:29:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21175#M15469</guid>
      <dc:creator>gsteiner</dc:creator>
      <dc:date>2013-08-12T06:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21176#M15470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got a test licesne for globalprotect HIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well I'm pretty sure now there is no way I can force a laptop user that he has to be connected to the vpn to be able to use the internet. In HIP I can't check if he can reach a public ip adress and there is also no way to place a firewall rule that would block his traffic if the vpn is not connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to buy now a Cisco VPN....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 06:39:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21176#M15470</guid>
      <dc:creator>gsteiner</dc:creator>
      <dc:date>2013-08-14T06:39:24Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21177#M15471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that with Global protect pre logon connexion + internal detection gateway detection, it should work.&lt;/P&gt;&lt;P&gt;If user is at home, GP agent will try to contact corp portal and create VPN connexion as soon as the laptop is started.&lt;/P&gt;&lt;P&gt;block the split tunneling (route 0.0.0.0/0 through VPN)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after that, on corp PA, create rule based on user, group, app ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mean all traffic have to go through vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 07:58:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21177#M15471</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-08-14T07:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21178#M15472</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If a user is at home, and for some reason, the VPN with HQ does NOT come up (for whatever reason), there is no way to prevent him to access the internet using his local internet line.&lt;/P&gt;&lt;P&gt;(The GlobalProtect client does not enforce a security policy on the local PC)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 08:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21178#M15472</guid>
      <dc:creator>${userLoginName}</dc:creator>
      <dc:date>2013-08-14T08:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21179#M15473</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What happens in the following situation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Client goes home and connects via wireless to his wifi network at home&lt;/P&gt;&lt;P&gt;2) GP automatically establishes a VPN to the office and sets the GP tunnel as the default route (0.0.0.0/0 -&amp;gt; GP tunnel)&lt;/P&gt;&lt;P&gt;3) Client now connects a 3G dongle to his laptop and establishes a 3G connection. The 3G connection now installs a 0.0.0.0/0 -&amp;gt; 3G&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This would allow the client to access the internet without going via GP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 12:52:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/21179#M15473</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2013-11-18T12:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: Forced VPN Connection with GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/1221899#M123394</link>
      <description>&lt;P&gt;Yes, it is possible. Here is the link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/enforce-globalprotect-for-network-access" target="_blank"&gt;https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-portals/enforce-globalprotect-for-network-access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR, Peter&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 10:36:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/forced-vpn-connection-with-globalprotect/m-p/1221899#M123394</guid>
      <dc:creator>segap</dc:creator>
      <dc:date>2025-02-25T10:36:06Z</dc:date>
    </item>
  </channel>
</rss>

