<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling Direct Access To Local Networks - GP VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-direct-access-to-local-networks-gp-vpn/m-p/68566#M39972</link>
    <description>&lt;P&gt;By default, if GP have a default route into the VPN, the client can still communicate with all devices on the local LAN. There are no security policies on the endpoint. This new feature is great, and restricts local LAN access for the client.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2015 18:01:38 GMT</pubDate>
    <dc:creator>gtomte</dc:creator>
    <dc:date>2015-11-24T18:01:38Z</dc:date>
    <item>
      <title>Disabling Direct Access To Local Networks - GP VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-direct-access-to-local-networks-gp-vpn/m-p/68552#M39961</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was wondering whether someone can provide me clarification on this feature.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo states&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"You can now disable direct access to local networks so that users cannot send traffic to proxies or local resources while connected to a GlobalProtect VPN. For example, if a user establishes a GlobalProtect VPN tunnel while connected to a public hotspot or hotel Wi-Fi, and this feature is enabled, all traffic is routed through the tunnel and is subject to policy enforcement by the firewall."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I was under the impression that security policies would enforce what a GP VPN client can access or not including&amp;nbsp;local networks as well as advising the access routes. &amp;nbsp;Are Palo saying local networks/zones/interfaces directly conneced to the firewall? &amp;nbsp;If the security policy allows access to proxies or local resources, surely this feature would be useless.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 15:40:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-direct-access-to-local-networks-gp-vpn/m-p/68552#M39961</guid>
      <dc:creator>indysogi</dc:creator>
      <dc:date>2015-11-24T15:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Direct Access To Local Networks - GP VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-direct-access-to-local-networks-gp-vpn/m-p/68557#M39964</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The way I understand it, GlobalProtect normally adds entries in the routing table so that trafic meant for your enterprise network (the access routes you configured) will go through the VPN tunnel, while the rest of the traffic will not. With this option, there will be only one route in your client computer: the one going to the VPN tunnel. This way, the client computer will not be able to talk directly to other network resources on his network (at home, for example).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 16:03:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-direct-access-to-local-networks-gp-vpn/m-p/68557#M39964</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2015-11-24T16:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling Direct Access To Local Networks - GP VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-direct-access-to-local-networks-gp-vpn/m-p/68566#M39972</link>
      <description>&lt;P&gt;By default, if GP have a default route into the VPN, the client can still communicate with all devices on the local LAN. There are no security policies on the endpoint. This new feature is great, and restricts local LAN access for the client.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 18:01:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-direct-access-to-local-networks-gp-vpn/m-p/68566#M39972</guid>
      <dc:creator>gtomte</dc:creator>
      <dc:date>2015-11-24T18:01:38Z</dc:date>
    </item>
  </channel>
</rss>

