<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153695#M50712</link>
    <description>&lt;P&gt;Correct on your description and I will check it out&lt;/P&gt;</description>
    <pubDate>Fri, 21 Apr 2017 21:02:07 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2017-04-21T21:02:07Z</dc:date>
    <item>
      <title>VPN Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153665#M50705</link>
      <description>&lt;P&gt;How do you configure the globalprotect VPN's so they won't route on the internal network but will only let users access it from outside the internal network&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 18:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153665#M50705</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-04-21T18:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153677#M50707</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Are you referring to&amp;nbsp;preventing internal users from connecting to the external GP gateway so they cannot VPN while on the internal network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 18:49:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153677#M50707</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-04-21T18:49:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153678#M50708</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Can you fill us in on how your setup looks currently so that we can actually give you the proper recommendation. Depending on how this was configured there are quite a few ways to actually accomplish this.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 18:53:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153678#M50708</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-04-21T18:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153686#M50709</link>
      <description>&lt;P&gt;Its set up with a gateway aand a protal using a loopback interface,tunnel, AD-LDAP authentication and we connect using the global protect client.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 19:23:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153686#M50709</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-04-21T19:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153694#M50711</link>
      <description>&lt;P&gt;So your internal users are connecting to the public facing IP of your gateway correct? If that is the case then you could just build a security policy to deny the internal zone to your public IP for example &lt;EM&gt;set rulebase security rules "Deny Internal Users to GP" from trust source 10.191.0.0/16 to untrust destination&amp;nbsp;174.175.176.178 action deny log-start no log-end yes &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Better yet if you have it in it's own zone then simply deny the internal users from your GP zone. As long as you allow traffic from your GP zone to your trust zone then you'll be good to go.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 20:58:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153694#M50711</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-04-21T20:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153695#M50712</link>
      <description>&lt;P&gt;Correct on your description and I will check it out&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2017 21:02:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-access/m-p/153695#M50712</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-04-21T21:02:07Z</dc:date>
    </item>
  </channel>
</rss>

