<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: global protect internal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1893#M1415</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the external gateway running now - so the external gateway should have the detect internal or both?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Mar 2013 20:41:00 GMT</pubDate>
    <dc:creator>felixn</dc:creator>
    <dc:date>2013-03-21T20:41:00Z</dc:date>
    <item>
      <title>global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1888#M1410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone give me some feedback on how to configure my globalprotect client to register/connect when on internal LAN? - so I can help my pan-user agent tag what users are connected&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 08:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1888#M1410</guid>
      <dc:creator>felixn</dc:creator>
      <dc:date>2013-03-21T08:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1889#M1411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think it is the same as an external gateway/portal.&lt;/P&gt;&lt;P&gt;Create a portal and gateway with the authentication you want (uncheck internal host detection), also add a new tunnel interface for the internal gateway. Should work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 14:14:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1889#M1411</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-03-21T14:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1890#M1412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This document will help you with the configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="3930" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 16:35:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1890#M1412</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-03-21T16:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1891#M1413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks guys - will check it out. This will also work with the external gateway right? - I am just not sure how it will "know" or is it because the check internal option is on the external?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 16:43:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1891#M1413</guid>
      <dc:creator>felixn</dc:creator>
      <dc:date>2013-03-21T16:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1892#M1414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The document only talks about the internal gateway. If you would like to configure both internal and external gateways, make sure to enable internal host detection so that users can connect when they are on LAN&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 20:34:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1892#M1414</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-03-21T20:34:59Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1893#M1415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the external gateway running now - so the external gateway should have the detect internal or both?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Mar 2013 20:41:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1893#M1415</guid>
      <dc:creator>felixn</dc:creator>
      <dc:date>2013-03-21T20:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1894#M1416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;GP will try to connect to the internal gtwy first and then if it does not it tries connecting to the external gateway.&lt;/P&gt;&lt;P&gt;Refer page 31 of the following doc:-&lt;A __default_attr="2020" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 00:57:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1894#M1416</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-03-22T00:57:50Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1895#M1417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't get it to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one portal with external and internal gateway and ssl authentication, I created one internal-gateway with no client-configuration. Here is some of the log files:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:956 Debug(4707): connect ssl.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:956 Debug( 168): nRequestTimeout is 10000&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:956 Debug(&amp;nbsp; 41): WSAGetLastError() returns 10035&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:988 Debug(4744): Internal gateway 10.119.20.1 is authenticated.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:988 Debug(4751): disconnect ssl.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:989 Info (11170): Gateway: 10.119.20.1, client IP: 10.119.20.106&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:989 Debug(5888): CPanMSService::RetrieveGatewayInfo, cert is 0000000000000000&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:989 Debug(5890): Pre-login gateway...&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:989 Debug( 849): Need to check gateway cert for 10.119.20.1&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:39:989 Info (14285): IPADDR=10.119.20.1,PORT=443,URL=/ssl-vpn/prelogin.esp,POST=1,POSTDATA="tmp=tmp&amp;amp;clientVer=4100",PROXY_AUTO=0,PROXY_CFGURL=NULL,PROXY=NULL,PROXY_BYPASS=NULL,PROXY_USER=NULL,PROXY_PASS=****,VERIFY_CERT=0,ADDITIONAL_CHECK=1&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:940 Debug(1698): Send response to client for request https_request&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Debug(14340): winhttpObj, cert error, 16.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Info (14427): HTTP_RPC, result is (NULL), len=0&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Debug(6018): Failed to pre-login to the gateway 10.119.20.1&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Error(4782): Failed to retrieve info from gateway 10.119.20.1.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Debug(4790): close http session.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Debug(4798): returns false.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Error(8891): NetworkDiscoverThread: failed to discover internal network.&lt;/P&gt;&lt;P&gt;(T7636) 03/25/13 15:54:44:977 Debug(8952): NetworkDiscoverThread: m_nPortalStatus is 1, m_bHasLoggedOnGateway is 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 15:11:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1895#M1417</guid>
      <dc:creator>felixn</dc:creator>
      <dc:date>2013-03-25T15:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1896#M1418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;at some point I got it working, but I had to add the external DNS name with the internal gw in my hosts file - related to some certificate stuff maybe?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clues?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Mar 2013 15:27:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1896#M1418</guid>
      <dc:creator>felixn</dc:creator>
      <dc:date>2013-03-25T15:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: global protect internal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1897#M1419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;did you tried to enter the internal IP to the DNS server? CN certificate = DNS name = IP&amp;nbsp; address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; - Your comman name (also alternative subject name) in your VPN server certificate will be verfied when you dial in with the DNS Name of the gateway. -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 09:26:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-internal/m-p/1897#M1419</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2013-03-26T09:26:23Z</dc:date>
    </item>
  </channel>
</rss>

