<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect prelogon and internal gateway detection in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-and-internal-gateway-detection/m-p/1222941#M123541</link>
    <description>&lt;P&gt;oof. so my "test" hotspot had wifi turned on while in hotspot mode. chaos ensued. In my defense, in previous hotspot, it did not allow wifi to be enabled prior to enabling the hotspot while this one lets it happen.&lt;BR /&gt;&lt;BR /&gt;With proper hotspot, the internal detection has happened more reliably now. My question still stands regarding "if prelogon's connection to its respective gateway happens, which by definition implies internal access to AD/DNS, what does the user-side do regarding the internal/external detection if it is defined in a portal agent config?"&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2025 20:09:25 GMT</pubDate>
    <dc:creator>BenKnorr2</dc:creator>
    <dc:date>2025-03-06T20:09:25Z</dc:date>
    <item>
      <title>GlobalProtect prelogon and internal gateway detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-and-internal-gateway-detection/m-p/1222930#M123539</link>
      <description>&lt;P&gt;I've been doing mixes of internal and external gateways with customer forever (I usually forget that "always-on" must be enabled for internal gateway detection to even be allowed in the first place).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm working on a pre-logon implementation that also would benefit from leveraging internal gateways/no-tunnel while inside the enterprise network. I'm seeing some wild behavior at the moment...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;THIS TEST IS OCCURRING WITH CLIENT CONNECTED TO CELLULAR HOTSPOT WITH IP ADDRESS ON PUBLIC INTERNET, OUTSIDE MY NGFW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Device, while on internet/outside UNTRUST zone on my NGFW, is configured to connect to my portal as "prelogon" : &lt;EM&gt;me.example.com.&lt;/EM&gt;&lt;/LI&gt;
&lt;LI&gt;Device successfully connects to prelogon portal, then EXTERNAL GP gateway, and is shown in NGFW GP-Gateway remote-users pane as "pre-logon" user as expected.&amp;nbsp;&lt;STRONG&gt;On the device at logon screen, however, it shows "&lt;EM&gt;Internal Gateway (Connected)"&lt;/EM&gt;&lt;/STRONG&gt;&lt;EM&gt;.&amp;nbsp; ... &lt;/EM&gt;[this is curious since the device is outside my WAN boundary]&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NGFW globalprotect external gateway status" style="width: 880px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66415iBABD9930147D76A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-03-06 at 11.26.49 AM.png" alt="NGFW globalprotect external gateway status" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;NGFW globalprotect external gateway status&lt;/span&gt;&lt;/span&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="internal gateway, while pre-logon is outside WAN" style="width: 200px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66414i20317553624D5C1D/image-size/small?v=v2&amp;amp;px=200" role="button" title="Screenshot 2025-03-06 at 11.23.39 AM.png" alt="internal gateway, while pre-logon is outside WAN" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;internal gateway, while pre-logon is outside WAN&lt;/span&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;I am able to login successfully on client, and GP client immediately shows that it is connected to internal gateway. On NGFW, it still shows "pre-logon" user on the external gateway.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gateway status" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/66416i4486ACCDCF3CB0FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-03-06 113028.png" alt="gateway status" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;gateway status&lt;/span&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;LI&gt;On client, doing test to &lt;A href="http://www.ifconfig.co" target="_blank" rel="noopener"&gt;www.ifconfig.co&lt;/A&gt;&amp;nbsp;, it shows WAN address of my GP external gateway, as if it were connected to the external gateway. The GP settings show no IP information, consistent with it thinking it is connected to internal GW.&amp;nbsp;&lt;EM&gt;ipconfig /all&lt;/EM&gt; shows NO tunnel interfaces, no tunnel information, no IP address other than the wifi address and gateway of my LTE hotspot I am connected to.&lt;BR /&gt;&lt;BR /&gt;ROUTE INFO ON CLIENT DURING THIS EVENT:&lt;BR /&gt;&lt;BR /&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;C:\Users\me&amp;gt;route print&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;===========================================================================&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Interface List&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;3...94 65 9c 1b be 1d ......Microsoft Wi-Fi Direct Virtual Adapter&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;15...94 65 9c 1b be 1c ......Intel(R) Dual Band Wireless-AC 7265&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1...........................Software Loopback Interface 1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;===========================================================================&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;IPv4 Route Table&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;===========================================================================&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Active Routes:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Network Destination Netmask Gateway Interface Metric&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;0.0.0.0 0.0.0.0 192.168.83.144 192.168.83.138 35&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;127.0.0.0 255.0.0.0 On-link 127.0.0.1 331&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;127.0.0.1 255.255.255.255 On-link 127.0.0.1 331&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;127.255.255.255 255.255.255.255 On-link 127.0.0.1 331&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;192.168.83.0 255.255.255.0 On-link 192.168.83.138 291&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;192.168.83.138 255.255.255.255 On-link 192.168.83.138 291&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;192.168.83.255 255.255.255.255 On-link 192.168.83.138 291&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;224.0.0.0 240.0.0.0 On-link 127.0.0.1 331&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;224.0.0.0 240.0.0.0 On-link 192.168.83.138 291&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;255.255.255.255 255.255.255.255 On-link 127.0.0.1 331&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;255.255.255.255 255.255.255.255 On-link 192.168.83.138 291&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;===========================================================================&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Persistent Routes:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;None&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;IPv6 Route Table&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;===========================================================================&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Active Routes:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;If Metric Network Destination Gateway&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 331 ::1/128 On-link&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;15 291 fe80::/64 On-link&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;15 291 fe80::a107:9e6c:1abc:8153/128&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;On-link&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;1 331 ff00::/8 On-link&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;15 291 ff00::/8 On-link&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;===========================================================================&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Persistent Routes:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;None&lt;/FONT&gt;&lt;/P&gt;
&lt;BR /&gt;192.168.83.0 is the internal network on my cellular hotspot and exists entirely outside of NGFW. NGFW knows nothing about this network from security, routing, NAT etc.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;NGFW logs show no traffic from source IP of this client. The only indications of connectivity on this client from the NGFW side is that I see a "pre-logon" user connected on this device through the external GP gateway. No traffic logs are generated from anything this client does. From the client side, I am able to access all "internal" resources as if I were connected via external GP gateway. ifconfig.co web page shows IP egress address as if I were connected to external GP gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My concern and misunderstanding is with how internal gateway detection works. It seems like at the pre-logon stage, the client successfully reaches the portal, gets a portal config which includes an internal gateway detection element and internal gateway defined. It seems like it is reaching out to an internal DNS server at the pre-logon stage (which I need it to be able to do in order to talk to Active Directory for user authentication at login prompt), and it thinks it is actually inside.&amp;nbsp;The user supplies credentials at login window and GlobalProtect shows "internal" after they login.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there some other way to handle this "internal detection" phase with pre-logon in the mix such that "pre-logon" is able to access AD for auth, but not allow the PTR lookup to succeed? Short of some DNS trickery where I create a zone that cannot be resolved in my pre-logon CIDR, I can't imagine how else to make this work. I've seen nothing in PAN documentation that suggests anything other than including an internal gateway is possible.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 18:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-and-internal-gateway-detection/m-p/1222930#M123539</guid>
      <dc:creator>BenKnorr2</dc:creator>
      <dc:date>2025-03-06T18:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect prelogon and internal gateway detection</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-and-internal-gateway-detection/m-p/1222941#M123541</link>
      <description>&lt;P&gt;oof. so my "test" hotspot had wifi turned on while in hotspot mode. chaos ensued. In my defense, in previous hotspot, it did not allow wifi to be enabled prior to enabling the hotspot while this one lets it happen.&lt;BR /&gt;&lt;BR /&gt;With proper hotspot, the internal detection has happened more reliably now. My question still stands regarding "if prelogon's connection to its respective gateway happens, which by definition implies internal access to AD/DNS, what does the user-side do regarding the internal/external detection if it is defined in a portal agent config?"&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 20:09:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-prelogon-and-internal-gateway-detection/m-p/1222941#M123541</guid>
      <dc:creator>BenKnorr2</dc:creator>
      <dc:date>2025-03-06T20:09:25Z</dc:date>
    </item>
  </channel>
</rss>

