<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect internal gateways in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211611#M61731</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20510"&gt;@Amory&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Does the reverse lookup work and resolves to the fqdn that you configured in the internal host detection?&lt;/P&gt;&lt;P&gt;How did you configure the internal gateway? Do you have there enabled tunnel mode (which shouldn't be done on the internal gateway)?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2018 21:55:45 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-04-24T21:55:45Z</dc:date>
    <item>
      <title>GlobalProtect internal gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211575#M61721</link>
      <description>&lt;P&gt;I'm struggling with GlobalProtect and always on.I have it configuerd for Multi-gateways and that part works great.&amp;nbsp; My issue is when I switch WiFi networks to internal, the globalprotect still tries to connect. I have added internal host detection and put down an IP and Hostname of a server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I disbale the globalprotect from systray. I'm able to ping this server. I enable Globalprotect and I'm still able to ping this server. then the always-on connects and I'm able to ping this server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now If I disconnect the wifi and switch to an internal wifi. I'm not able to ping this server or anything. its like Globalprotect has all my traffic trying to go through the globalprotect virtual adapter.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The moment I disable globalprotect again. I'm now able to ping this device again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am I missing??? why is it doing this? anyone have this same issue.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 18:46:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211575#M61721</guid>
      <dc:creator>Amory</dc:creator>
      <dc:date>2018-04-24T18:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect internal gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211590#M61723</link>
      <description>&lt;P&gt;If you have "No direct access to local network" enabled in your globalprotect gateway, globalprotect will "have all your traffic try to go through the globalprotect virtual adapter" - you will be able to see this in your routing table on your workstation ("route print" in windows)&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 19:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211590#M61723</guid>
      <dc:creator>JoeAndreini</dc:creator>
      <dc:date>2018-04-24T19:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect internal gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211591#M61724</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20510"&gt;@Amory&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you actually have an internal gateway specified or are you simply using the Internal Host Detection? If you have an internal gateway specified are you doing FQDN or IP, and do you actually have a internal DNS object for the FQDN address if that's what you are using?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 19:45:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211591#M61724</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-24T19:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect internal gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211592#M61725</link>
      <description>&lt;P&gt;I do have an internal gateway listed. it's the same one I would get from DHCP on the internal WiFi. I have the IP listed not the FQDN.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 20:10:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211592#M61725</guid>
      <dc:creator>Amory</dc:creator>
      <dc:date>2018-04-24T20:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect internal gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211611#M61731</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/20510"&gt;@Amory&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Does the reverse lookup work and resolves to the fqdn that you configured in the internal host detection?&lt;/P&gt;&lt;P&gt;How did you configure the internal gateway? Do you have there enabled tunnel mode (which shouldn't be done on the internal gateway)?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 21:55:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211611#M61731</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-04-24T21:55:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect internal gateways</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211866#M61774</link>
      <description>&lt;P&gt;I found the solution. Under the portal and in the App settings. the option for enforce GlobalProtect Connection for Network Access was set to yes. So I guess with Always-On method that means that all network traffic will go throught GloblaProtect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for everyone that provided input.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Apr 2018 13:37:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-internal-gateways/m-p/211866#M61774</guid>
      <dc:creator>Amory</dc:creator>
      <dc:date>2018-04-26T13:37:05Z</dc:date>
    </item>
  </channel>
</rss>

