<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disabling GP client but where are the logs kept? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210964#M61564</link>
    <description>&lt;P&gt;not sure what you are asking but i have a similar issue with a group of users that are allowed to disconnect VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I simply placed them in an AD group "Disable-GP" and now they get a different config to the default users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no password needed really...&lt;/P&gt;</description>
    <pubDate>Thu, 19 Apr 2018 14:15:06 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-04-19T14:15:06Z</dc:date>
    <item>
      <title>Disabling GP client but where are the logs kept?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210863#M61552</link>
      <description>&lt;P&gt;Does anyone know if anything is logged on the firewall side when someone disables the GP client? We require a password to be entered when the client is disabled but I am not finding anything in the system logs that can be related to the event.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously we dont want to allow users to just bypass all fo the security provided by the firewall by disabling the client on a corporate device but it is causing quite an uproar with the high salaried&amp;nbsp;individuals that they cannot disable the client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Closest thing I can find is event globalprotectgateway-agent-msg containing Override(s) = 1 or = 2 but not sure if that is it because in a test I didnt see one of these entries for a user that disabled the client while I was watching the log&lt;/P&gt;</description>
      <pubDate>Wed, 18 Apr 2018 23:22:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210863#M61552</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-04-18T23:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling GP client but where are the logs kept?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210964#M61564</link>
      <description>&lt;P&gt;not sure what you are asking but i have a similar issue with a group of users that are allowed to disconnect VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I simply placed them in an AD group "Disable-GP" and now they get a different config to the default users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;no password needed really...&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 14:15:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210964#M61564</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-04-19T14:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling GP client but where are the logs kept?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210969#M61569</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;I thought about doing this. If I add a new config (gateway-&amp;gt;Agent-&amp;gt;Client settings-&amp;gt;Add) I assume I just need to have the "exception" config above the "everyone else" config since all users will be in the regular VPN group but only a few would be in the disable exception group..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly I feel so wrong allowing this at all, but sometimes security has no teeth when it comes to what the C or VP level wants &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would still like to be able to report on who/how often/when someone disables the client but I am not sure that is possible at this time&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 15:00:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210969#M61569</guid>
      <dc:creator>hshawn</dc:creator>
      <dc:date>2018-04-19T15:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Disabling GP client but where are the logs kept?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210971#M61571</link>
      <description>&lt;P&gt;yes, above the default...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;logging will be local to device...&amp;nbsp;(if any)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i agree with you re security&amp;nbsp;but if I do as I'm told then as far as I'm concerned my ass is coverd...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have you looked at the option of allow user to disable with ticket...&amp;nbsp;&amp;nbsp; it's not for me but may help with frequency of use...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also...&amp;nbsp;&amp;nbsp; do you use HIP, if so then you could find the reg setting for client disabled and add a custom check.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW, our users are still limited to what they can do when disconnected. they are still unable to browse the internet. we just allow the disable option to allow local printing. It's better than allowing split tunneling...&lt;/P&gt;</description>
      <pubDate>Thu, 19 Apr 2018 15:13:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/disabling-gp-client-but-where-are-the-logs-kept/m-p/210971#M61571</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-04-19T15:13:51Z</dc:date>
    </item>
  </channel>
</rss>

