<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyone ever use “internal host detection” on GP? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184691#M56614</link>
    <description>&lt;P&gt;to confirm...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;internal host detection does not work with "on demand".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i suppose the intention for this is to prevent "always on " from auto connecting when not needed as the user will have no intervention.&lt;/P&gt;</description>
    <pubDate>Tue, 31 Oct 2017 09:59:25 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-10-31T09:59:25Z</dc:date>
    <item>
      <title>Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184246#M56519</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone ever use “internal host detection” on GP? For some reason it does not try to do the test. I checked the GP services log and did not find an entry there. I am trying to force "enforce GlobalProtect for Network Access" when users are cocnneced to the internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2017 23:37:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184246#M56519</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-27T23:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184284#M56525</link>
      <description>&lt;P&gt;Works ok for me,&amp;nbsp;&lt;/P&gt;&lt;P&gt;globe displays little house, more like a dogs kennel when connected to lan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not using enforce option, just always on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i did have to allow globalprotect connection frm lan to wan for users to get GP config for the first connection attempt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 08:06:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184284#M56525</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-28T08:06:37Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184292#M56529</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the Always on option did you get a one time password to work with LDAP? I am not sure how to get OTP working as Windows logon screen only allows user name and password and with SSO enabled it will only carry username and password.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thansk&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 12:56:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184292#M56529</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-28T12:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184297#M56531</link>
      <description>&lt;P&gt;I am confused by your reply... &amp;nbsp;never seen otp with ldap...&lt;/P&gt;&lt;P&gt;could you explain in more detail your authentication process.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 20:16:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184297#M56531</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-28T20:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184298#M56532</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Want I want is Global Protect to be set to User-Logon. CLient logs on to Windows 7 SSO takes creds and supplies it to Portal. Then for Gateway it promotes user for RADIUS RSA OTP. I can get this to work without SSO, but I want to use&amp;nbsp;&lt;SPAN&gt;User-Logon SSO. I want it so i promotes user for PIN when they login to the PC. If its added to the main windows logon page then there can be an issue when they are on the local network and GP is not needed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 20:53:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184298#M56532</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-28T20:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184299#M56533</link>
      <description>&lt;P&gt;Still not quite sure what you are trying to achieve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you cannot mix sso with otp. Sso will only use windows credentials.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;our users do enter a pin before logon to windows but this is via bitlocker disk encryption.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;globalprotect cannot modify the windows logon process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 21:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184299#M56533</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-28T21:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184300#M56534</link>
      <description>&lt;P&gt;ok thanks you have answered my question cannot have a mix of both SSO and OTP. Have you gotten "enforce GlobalProtect for Network Access disable when on internal network" and "Internal Host Detection" to work on user-connect method? It is not working for me. When I check the GPS*log it does not show it trying to do the DNS resolution on the internal name I&amp;nbsp;provided.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 21:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184300#M56534</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-28T21:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184301#M56535</link>
      <description>&lt;P&gt;I have a client that wants to use OTP and always on but I am guessing this is not possible.&lt;/P&gt;</description>
      <pubDate>Sat, 28 Oct 2017 21:29:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184301#M56535</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-28T21:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184316#M56537</link>
      <description>&lt;P&gt;Are you saying that the GP client just connects as normal or does it not connect at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only ask this because the GP client needs to make connection when first installed to obtain the settings for internal host detection.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 07:44:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184316#M56537</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-29T07:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184320#M56538</link>
      <description>&lt;P&gt;Otp and always on... i dont see why not. But make sure for otp that you configure authentication overide in both portal and gateway config or the gateway will try to use the same otp and fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may be better off by adding this as a new post.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 09:30:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184320#M56538</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-29T09:30:02Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184323#M56540</link>
      <description>&lt;P&gt;I did connect to portal to pull down new configuration, but it seems "internal host detection" does not work with on-demand method&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 10:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184323#M56540</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-29T10:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184333#M56543</link>
      <description>&lt;P&gt;Ok it may just be that it’s not needed for on demand mode, i suppose you’d need to ask yourself why would you even try to connect when on the local network. In that case i suppose it only works for always on to prevent auto connecting on lan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;somebody else may have the answer here but I’m going to try it on monday/tuesday so if you find the answer, please update this post.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 12:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184333#M56543</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-29T12:12:24Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184336#M56545</link>
      <description>&lt;P&gt;Ok will do.. Pretty much requirment is OTP and to enforce global protect to connect from external network. Internal network does not GP. This works fine with LDAP and user-logon. It does not work with&amp;nbsp;&lt;EM&gt;on-demand.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Thanks&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 15:44:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184336#M56545</guid>
      <dc:creator>junior_r</dc:creator>
      <dc:date>2017-10-29T15:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Anyone ever use “internal host detection” on GP?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184691#M56614</link>
      <description>&lt;P&gt;to confirm...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;internal host detection does not work with "on demand".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i suppose the intention for this is to prevent "always on " from auto connecting when not needed as the user will have no intervention.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 09:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/anyone-ever-use-internal-host-detection-on-gp/m-p/184691#M56614</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-31T09:59:25Z</dc:date>
    </item>
  </channel>
</rss>

