<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic couple of questions relevant to global protection feature in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8178#M6044</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Hello all. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;I have a couple of questions about Global Protection feature. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;1. If I configured Global Protection for external users, is it possible to block for network access for specific user who doesn't has latest patch or latest anti-virus?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;2. if it is possible, can i configure redirection to warning msg for those specific user?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;3. Does global protection must connect with SSL VPN?? Is it impossible without SS LVPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;4. if it is possible to apply global protection without SSL VPN, I’d like to apply to internal users of firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;5. If I configured Global Protection, is it able to apply for internal users of firewall (paloalto L3 mode) without SSL VPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Eugene. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Oct 2011 09:29:31 GMT</pubDate>
    <dc:creator>willstech</dc:creator>
    <dc:date>2011-10-05T09:29:31Z</dc:date>
    <item>
      <title>couple of questions relevant to global protection feature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8178#M6044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Hello all. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;I have a couple of questions about Global Protection feature. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;1. If I configured Global Protection for external users, is it possible to block for network access for specific user who doesn't has latest patch or latest anti-virus?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;2. if it is possible, can i configure redirection to warning msg for those specific user?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;3. Does global protection must connect with SSL VPN?? Is it impossible without SS LVPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;4. if it is possible to apply global protection without SSL VPN, I’d like to apply to internal users of firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;5. If I configured Global Protection, is it able to apply for internal users of firewall (paloalto L3 mode) without SSL VPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Eugene. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 09:29:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8178#M6044</guid>
      <dc:creator>willstech</dc:creator>
      <dc:date>2011-10-05T09:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: couple of questions relevant to global protection feature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8179#M6045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Eugene,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answers as below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;1. If I configured Global Protection for external users, is it possible to block for network access for specific user who doesn't has latest patch or latest anti-virus?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Global Protect is not NAC solution. You can control what access users can have when the traffic pass through the firewall, but not before it passess through the firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt; &lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;2. if it is possible, can i configure redirection to warning msg for those specific user?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;No. But youcan have some message from the agent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt; &lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;3. Does global protection must connect with SSL VPN?? Is it impossible without SS LVPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Yes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;4. if it is possible to apply global protection without SSL VPN, I’d like to apply to internal users of firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Yes&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;5. If I configured Global Protection, is it able to apply for internal users of firewall (paloalto L3 mode) without SSL VPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Yes&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Oct 2011 11:43:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8179#M6045</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-10-10T11:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: couple of questions relevant to global protection feature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8180#M6046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;While the Global Protect config guide will help you with your initial setup, it will not be your final solution.&amp;nbsp; There are many things that are missing in the guide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 13:52:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8180#M6046</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T13:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: couple of questions relevant to global protection feature</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8181#M6047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done extensive setup and testing for GP in my environment.&amp;nbsp; I have answered your questions below, per my experience and testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;1. If I configured Global&amp;nbsp; Protection for external users, is it possible to block for network&amp;nbsp; access for specific user who doesn't has latest patch or latest&amp;nbsp; anti-virus?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;SPAN style="color: #ff0000;"&gt;-Yes.&amp;nbsp; I just want to clarify though, when you say 'external users' do u mean members of your domain but connecting externally?&amp;nbsp; If yes, then create a HIP Profile with objects defined with the match that you want.&amp;nbsp; You then need to apply that HIP profile to a security policy to 'deny' access to http and https, if you want to block them from surfing. Creating the HIP is tricky though for a Deny Policy, make sure that you configure it the way you want it to be configed.&amp;nbsp; I.E. the Virus definition timeframe. I would suggest configuring the product version rather than the virus definition timeframe, this provides a little more of a solid check.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;2. if it is possible, can i configure redirection to warning msg for those specific user?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #ff0000; "&gt;- Kind of.&amp;nbsp; If you have a user that receives a HIP message stating that they are not compliant, you can have the message say anything you want.&amp;nbsp; For instance, if I have a user in my environment that is not compliant, the message says "Your client is not compliant because "enter reason here".&amp;nbsp; Please contect your systems administrator for assistance."&amp;nbsp; This will allow you to know what is wrong and why they are not able to connect to resources.&amp;nbsp; But test to ensure that the HIP is setup exactly how you want to save headache from people calling you all the time to fix it.&amp;nbsp; Furthermore, there needs to be a deny rule in place to not allow them access to resources if they are not compliant.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #ff0000; "&gt;For instance:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #ff0000; "&gt;In my environment...currently we only want clients that are part of our domain to have access to resources whether they access through the internal or external gateway.&amp;nbsp; This is so any Joe Schmo laptop cannot come inside and access our network.&amp;nbsp; Or if a client that is not part of our domain tries to access through the external gateway they are denied access to everything.&amp;nbsp; So we have a HIP profile in place that checks if they are or are not part of our domain.&amp;nbsp; If they are part, they are 'allowed' access, if they are not part of our domain they are 'denied'.&amp;nbsp; When the deny rule is matched, the client cannot surf the internet or have access to internal resources.&amp;nbsp; &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #ff0000; "&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;3. Does global protection must connect with SSL VPN?? Is it impossible without SS LVPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;SPAN style="color: #ff0000;"&gt;-Yes.&amp;nbsp; Absolutlely!&amp;nbsp; We run GP all the time with single sign on without VPN.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;4. if it is possible to apply global protection without SSL VPN, I’d like to apply to internal users of firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;&lt;SPAN style="color: #ff0000;"&gt;-Yes.&amp;nbsp; We do this also.&amp;nbsp; You just have to configure an internal gateway and an external gateway.&amp;nbsp; Keep in mind that GP will always try to connect to the internal gateway first after it authenticates through the portal.&amp;nbsp; But, in my opinion, best practice to to just configure 2 serperate gateways...internal and external.&amp;nbsp; Make sure that the internal gateway has an internal IP address.&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="min-height: 8pt; padding: 0px;"&gt;&lt;SPAN lang="EN-US"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;5.&amp;nbsp; If I configured Global Protection, is it able to apply for internal&amp;nbsp; users of firewall (paloalto L3 mode) without SSL VPN Connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #ff0000; "&gt;-Yes. See answer to #4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN lang="EN-US"&gt;Side notes.&amp;nbsp; Make sure that you test all angles of global protect before implementing.&amp;nbsp; It works great once everything is configured properly.&amp;nbsp; And in my testing and config, it takes some time to learn everything that needs to be done to ensure that it works right.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Oct 2011 15:14:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/couple-of-questions-relevant-to-global-protection-feature/m-p/8181#M6047</guid>
      <dc:creator>kamish</dc:creator>
      <dc:date>2011-10-11T15:14:46Z</dc:date>
    </item>
  </channel>
</rss>

