<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP Internal Host Detection not Working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74877#M41809</link>
    <description>&lt;P&gt;Make sure that the connection method configured in the portal is "user-logon" and not on-demand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Gerardo.&lt;/P&gt;</description>
    <pubDate>Thu, 17 Mar 2016 13:12:10 GMT</pubDate>
    <dc:creator>glastra1</dc:creator>
    <dc:date>2016-03-17T13:12:10Z</dc:date>
    <item>
      <title>GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74314#M41658</link>
      <description>&lt;P&gt;To start off...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have already read this.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-not-Detecting-Internal-Network-with-Internal-Host/ta-p/53681" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/GlobalProtect-not-Detecting-Internal-Network-with-Internal-Host/ta-p/53681&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll start off with the whole story. We have 2 ISP's, setup to our PA-500's using 2 VR's. One was setup for the DMZ Zone, with it's default out ISP 1. The Second VR was users internet, with the deafult route out ISP 2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Initially GP was set up on ISP 1. Thus when users attempted to connect their sesssion would be NATed out ISP 2 back into ISP 1, with internal host detection working a treat and showed the little house on the GP sys tray icon.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My goal was to move all my services over to ISP 2. Turns out I couldn't just copy the existing NAT rules since the DMZ default route was out ISP 1, and any connection attempts would fail to due an incomplete hand shake. Welcome &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Symmetric-Return/ta-p/59374" target="_self"&gt;Symmetric Return&lt;/A&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So I got all my services to work with either external IP association. I then go to move our VPN to the shaw side using both proper DNS lookup for the portal/gateway and our own internal PKI. I fought tooth n nail and got the internal PKI setup workign just the way I want it to. Externally wokring a treat, so I attempt to connect internally, to my dismay I couldn't reach the external portal from inside the network. Checking my monitor Tab on the PA's I see no blocked traffic, I now it was getting droped somewhere in the PA, so i do a packet capture. Low and behold, my packets are geting dropped.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After talking to my uber smart network engineer, we had two options (NoNAT to my ISP 2 pub IP, or do a &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-U-Turn-NAT/ta-p/61889" target="_self"&gt;UTurn NAT&lt;/A&gt; to my ISP pub IP)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After making this config, I could ping and access the web portal no prob! YAY!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And finally to the point of this post, everything works now except internal host detection. and it's driving me up the wall, everything I read on it and how I know my configs are it should just work at this point. But it keeps connecting my client to the VPN DHCP pool and saying its connected and I can see the traffic on teh client system. Even though it's internally connected, (I can ping and resolve the internal host detection stuff from the client system perfectly fine)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;to make it even weirder, When I change my portal IP to the ISP 1, internal host dtecttion works a treat&lt;BR /&gt;change it back to ISP 2, and interanal host detection fails.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;same internal host detection settings on both portal/user configs, same internal network.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thoughts? I'm bashing my head on this one...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 20:04:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74314#M41658</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2016-03-07T20:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74381#M41673</link>
      <description>&lt;P&gt;Hi Zewwy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What does the PanGP Services log say? Look for a line that contains "DnsQuery returns " and the lines right before and after it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Tue, 08 Mar 2016 16:06:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74381#M41673</guid>
      <dc:creator>BenjAudy.MTL</dc:creator>
      <dc:date>2016-03-08T16:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74598#M41734</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the reply. I did the following.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I cleared the PanGPS.log file. I connected via the ISP 1 portal, and sure enough I get DNSQuery response 0&lt;/P&gt;
&lt;P&gt;As it should be. I clear the log by renaming it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I change my portal address on my GlobalProtect, connects sayign externally. I then check the PANGPS.log and I don't find a single DnsQuery line in the log at all, as if it's not even trying to do internal host detection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 18:39:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74598#M41734</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2016-03-11T18:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74877#M41809</link>
      <description>&lt;P&gt;Make sure that the connection method configured in the portal is "user-logon" and not on-demand.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards,&lt;/P&gt;
&lt;P&gt;Gerardo.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2016 13:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/74877#M41809</guid>
      <dc:creator>glastra1</dc:creator>
      <dc:date>2016-03-17T13:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/77417#M42593</link>
      <description>&lt;P&gt;Hey Gerardo,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks so much for the suggestion. I was working with a PAN tech on the case (tier one) so had to argue about a couple things he wasn't understanding about the device, haha.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We tried you answer on my own account by me changing my AD user membership, and then re-newing the PAN's user mappings, and then I found I had to create a new profile (I'm sure possibly a uninstall, or even a registry edit could have resolved it but I didn't know exactly what to look for so I simply re-created my profile) before it would change from on-demnd mode to user-logon. I asked the tech for any documentation that would state why this is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can understand as since it's on-Demand that the user wouldn't normally connect internally, but then whats the point of teh internal host detection being available for edit when the type is set to on-demand. Seems like a UI bug or something that was merely overlooked and was just never thought of and conisdered as-is.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One last thing I noticed when I was testing and that was that the user cert I install on users system that goes into their personal certificate store of the user, when I created a new user an AD and logged into that user on a system I had installed the cert for another user, taht cert is already in the new users certificate store... I found this baffeling. The other weird part is when I removed my profile to fix the on-demand problem I noticed it removed my certificate from the store, more along the lines to be expected with a profile wipe.&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2016 14:14:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/77417#M42593</guid>
      <dc:creator>Zewwy</dc:creator>
      <dc:date>2016-05-03T14:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/104729#M44722</link>
      <description>&lt;P&gt;I'm having a similar issue, I am try to enable internal host detection. But the GP client keeps trying to contact our external gateway and failing with "invalid gateway", so it never gets to the internal detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure how to U-turn NAT it, because the GP gateway doesn't have internal IP address.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2016 19:01:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/104729#M44722</guid>
      <dc:creator>Maxstr</dc:creator>
      <dc:date>2016-08-19T19:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/106128#M44789</link>
      <description>&lt;P&gt;Make sure for the host name that you are using the FQDN (ie test.mydomain.com and not just test).&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2016 15:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/106128#M44789</guid>
      <dc:creator>nwetech</dc:creator>
      <dc:date>2016-08-23T15:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: GP Internal Host Detection not Working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/184302#M56536</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone confirm if&amp;nbsp;&lt;SPAN&gt;on-Demand and "Internal Host Detection" will work? I have my configuration set to on-demand and have "enforce GlobalProtect for Network Access". I need a way to disable this when user is on the inernal network. I cannot go down the path of user-logon as the client is using OTP for VPN so SSO wont work&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 21:37:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-internal-host-detection-not-working/m-p/184302#M56536</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-28T21:37:38Z</dc:date>
    </item>
  </channel>
</rss>

