<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Best Practices in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36386#M26752</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark96,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is "Internal Host Detection" checked in setup. Refer following snapshot for it. If its checked than uncheck it, it should not connect.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Internal_Host_Detection.JPG.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16679_Internal_Host_Detection.JPG.jpg" style="height: 365px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Oct 2014 22:28:22 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2014-10-30T22:28:22Z</dc:date>
    <item>
      <title>Global Protect Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36384#M26750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have deployed Global Protect with Single Sign on and have internal host detection.&amp;nbsp;&amp;nbsp; I have everything working and connecting fine, I have one portal and 3 gateways. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I have seen is that some internal clients are connecting to an internal gateway, either by choosing to, or by accident.&amp;nbsp; I have not setup an internal gateway and now I am thinking I should.&amp;nbsp;&amp;nbsp; Any guides or suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 21:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36384#M26750</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2014-10-30T21:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36385#M26751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Few related DOC for your reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2020"&gt;GlobalProtect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4923"&gt;Global_Protect_PAN_OS5.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3930"&gt;How to Configure Internal GlobalProtect Only&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5847"&gt;How Often does GlobalProtect Client Try to Connect to the Gateway for Internal-Only GlobalProtect?&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 21:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36385#M26751</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-10-30T21:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36386#M26752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark96,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is "Internal Host Detection" checked in setup. Refer following snapshot for it. If its checked than uncheck it, it should not connect.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Internal_Host_Detection.JPG.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16679_Internal_Host_Detection.JPG.jpg" style="height: 365px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 22:28:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36386#M26752</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-30T22:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36387#M26753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it is checked and when the laptop docs the icon shows it is internal, but a user can right click and manual connect to a gateway and it will connect.&amp;nbsp;&amp;nbsp;&amp;nbsp; Sorry I stated the issue wrong, an internal client and connect to an external gateway.&amp;nbsp;&amp;nbsp; I need to prevent that from happening. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 23:00:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36387#M26753</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2014-10-30T23:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Best Practices</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36388#M26754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following solution will work in GPC 2.1. User can not modify any IP in portal config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;1. open regedit.exe &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;2. Go to HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings\ &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;3. Right Click &amp;gt; New &amp;gt; String Value &amp;gt; can-change-portal &amp;gt; Value "No" &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;Or you can try disabling "Advance view".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;&lt;IMG alt="advance.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/16680_advance.PNG" style="height: 462px; width: 620px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #e3f3ff;"&gt;Hardik Shah&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Oct 2014 23:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-best-practices/m-p/36388#M26754</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-30T23:17:39Z</dc:date>
    </item>
  </channel>
</rss>

