<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I configure Global Protect for on-demand as well as pre-logon in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17914#M13040</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you can build a separate portal profile and have it setup using OnDemand. Or worst case you can build a separate VSYS and in that separate VSYS you can build a separate portal config. This is from memory though so don't quote me on this, I'm too lazy to go look all this up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Feb 2014 14:18:45 GMT</pubDate>
    <dc:creator>ericgearhart</dc:creator>
    <dc:date>2014-02-10T14:18:45Z</dc:date>
    <item>
      <title>How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17913#M13039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a scenario whereby I need to offer an on-demand VPN solution to untrusted endpoints as well as an always-on solution for my trusted endpoints. Running through guides I have been able to run a pre-logon VPN that has successfully allowed me to authenticate the workstation then make use of User-ID to identify and allow users into the network based on various rules however I need to also offer an on-demand function that will allow staff using untrusted endpoints to connect to the network and access a very restricted set of resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anyone has done this or knows the methodology then please do let me know&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 09:54:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17913#M13039</guid>
      <dc:creator>mwhite</dc:creator>
      <dc:date>2014-02-10T09:54:50Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17914#M13040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think you can build a separate portal profile and have it setup using OnDemand. Or worst case you can build a separate VSYS and in that separate VSYS you can build a separate portal config. This is from memory though so don't quote me on this, I'm too lazy to go look all this up.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 14:18:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17914#M13040</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2014-02-10T14:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17915#M13041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Matt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using a single GP portal, you can specify multiple&amp;nbsp; "User/user Group"&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt; ,&lt;/SPAN&gt;&lt;/SPAN&gt; where you have an optionto define different connect method.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example: For Untrusted user select connect method= On-demand&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; For &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;trusted user&lt;/SPAN&gt;&lt;/SPAN&gt; select connect method = pre-logon&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="11505" alt="globalP.JPG.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11505_globalP.JPG.jpg" style="width: 620px; height: 420px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Feb 2014 15:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17915#M13041</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-02-10T15:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17916#M13042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks - the issue that I have will be the endpoint that the user connects from rather than the users themselves. they should be able to connect pre-logon from their corporate laptop but if they work from home on a non-corp device they should be able to use GP on-demand to gain access to a second restricted network that only permits them access to an RDS server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Feb 2014 11:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17916#M13042</guid>
      <dc:creator>mwhite</dc:creator>
      <dc:date>2014-02-28T11:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17917#M13043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to make a similar configuration but I haven't been able, I tried &lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt; method but the problem is that for the config I need, the same user should have the ability to have an always on connection for the internal gateway and&amp;nbsp; an on-demand connection for external gateways. No luck so far ... Any advice?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Jul 2014 01:07:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17917#M13043</guid>
      <dc:creator>hopcio</dc:creator>
      <dc:date>2014-07-09T01:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17918#M13044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am also trying to do the same thing. I want them connected when at work (always-on), but when out of the office, I want the user to be able to enable on-demand. This seems like a pretty obvious use case. Surprised you can't do it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Jun 2015 19:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17918#M13044</guid>
      <dc:creator>pwebber</dc:creator>
      <dc:date>2015-06-30T19:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17919#M13045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may create another portal and GW and allow users changing portal address on their GP agents. To avoid certificate issues, I would deploy this new portal using the same address but a different TCP port than default (443). To do this, a loopback interface can be used to support the GP portal and a NAT policy should be implemented to redirect traffic to the loopback interface on port 443.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jul 2015 07:02:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17919#M13045</guid>
      <dc:creator>ACortes</dc:creator>
      <dc:date>2015-07-07T07:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17920#M13046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not tested this, but probably something like this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5986" title="https://live.paloaltonetworks.com/docs/DOC-5986"&gt;https://live.paloaltonetworks.com/docs/DOC-5986&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with &lt;STRONG style="font-size: 11.6999998092651px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1856" data-externalid="" data-presence="null" data-userid="19491" data-username="HULK" href="https://live.paloaltonetworks.com/people/HULK" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; color: #006595;"&gt;HULK&lt;/A&gt; &lt;/STRONG&gt;&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 11.6999998092651px;"&gt;Feb 10, 2014 7:37 AM &lt;/SPAN&gt;&lt;SPAN class="font-color-meta-light j-thread-replyto" style="padding: 0 0 0 3px; font-size: 11.6999998092651px; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #a9a9a9;"&gt;(&lt;A _jive_internal="true" class="font-color-meta-light localScroll" href="https://live.paloaltonetworks.com/thread/9917#37436" style="font-weight: inherit; font-style: inherit; font-size: 11.6999998092651px; font-family: inherit; color: #a9a9a9;" title="Go to message"&gt;in response to mwhite@wavex.co.uk&lt;/A&gt;)&lt;/SPAN&gt; suggestion ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Victor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jul 2015 20:00:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17920#M13046</guid>
      <dc:creator>vcappuccio</dc:creator>
      <dc:date>2015-07-08T20:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I configure Global Protect for on-demand as well as pre-logon</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17921#M13047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding internal trusted computers and external untrusted computers:&lt;/P&gt;&lt;P&gt;You may be able to use DNS to help if your internal DNS is separate from your Internet facing DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have two gateways with different IP's. One is prelogin (.1 for this example) and the other on-demand (.2)&lt;/P&gt;&lt;P&gt;Use one name in the client (ex. connect.xyz.com)&lt;/P&gt;&lt;P&gt;Internal users:&lt;/P&gt;&lt;P&gt;Internal DNS resolves connect.xyz.com to the .1 IP and users connect prelogon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;External untrusted users:&lt;/P&gt;&lt;P&gt;External DNS resolves connect.xyz.com to the .2 IP and users connect on demand. (assuming this doesn't use certificates for authentication)&lt;/P&gt;&lt;P&gt;Or, have a totally separate name and IP for external users to connect to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jul 2015 14:13:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-configure-global-protect-for-on-demand-as-well-as-pre/m-p/17921#M13047</guid>
      <dc:creator>skusnarowis</dc:creator>
      <dc:date>2015-07-09T14:13:33Z</dc:date>
    </item>
  </channel>
</rss>

