<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: To force client to switch to internal network in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239832#M68709</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;just added it for internal host detection&lt;/P&gt;</description>
    <pubDate>Wed, 14 Nov 2018 13:55:21 GMT</pubDate>
    <dc:creator>Radmin_85</dc:creator>
    <dc:date>2018-11-14T13:55:21Z</dc:date>
    <item>
      <title>To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239780#M68693</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;we have mobile clients with GP which use corporate notebooks at home .It was configured user logon option to force the notebook to connect through GP when it connects to home WI-FI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the same worker comes back to workplace and plugged in the ethernet cable they still use the same GP network&lt;/P&gt;&lt;P&gt;Is there any way to force the client notebook to recognize the internal network and dont use GP&amp;nbsp; with user logon option in place?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 08:53:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239780#M68693</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-14T08:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239788#M68694</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can configure internal gateway (without tunnel mode) and make use of '&lt;SPAN&gt;Internal Host Detection' in agent configuration to determine if host is within the network or outside the network.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can find more information in the below link.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/globalprotect/network-globalprotect-portals/globalprotect-portals-agent-configuration-tab/globalprotect-portals-agent-internal-tab&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 09:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239788#M68694</guid>
      <dc:creator>Rajesh12</dc:creator>
      <dc:date>2018-11-14T09:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239792#M68695</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100390"&gt;@Rajesh12&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes we did it but the problem is when PA try to connect to that gateway (without tunnel mode) it asks for certificate and we use the same certificate (company certificate) which we use to connect to&amp;nbsp; PA outside&amp;nbsp; network (which is ok) it says Bad request&lt;/P&gt;&lt;P&gt;So as i understand the host could not reach to portal even to see the internal host identification and that is why can not recognize internal network&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 10:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239792#M68695</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-14T10:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239799#M68696</link>
      <description>&lt;P&gt;can you post a screen shot of your agent/gateways setting.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 10:56:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239799#M68696</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-14T10:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239801#M68698</link>
      <description>&lt;P&gt;sorry just read all your post. do you know why your getting the cert error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yesy the client still connects to the portal befor internal host detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 11:11:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239801#M68698</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-14T11:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239809#M68700</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;i guess i even can not connect to Portal too&lt;/P&gt;&lt;P&gt;Because normally when i type in browser the internal gateway i must get into the page where i usually download the GP agent app.But i even can not do it.It ask for certificate and then when i use certificate it says bad request&lt;/P&gt;&lt;P&gt;IT is everything ok when i do it outside the network,But the problem is when i try to connect inside the corporate network&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 12:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239809#M68700</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-14T12:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239812#M68701</link>
      <description>&lt;P&gt;Not sure what you mean by internal gateway!&amp;nbsp; you do not need one for internal host detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here is my setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inthost.png" style="width: 517px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17537iE0ADF4E4FA0C639E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="inthost.png" alt="inthost.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 12:08:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239812#M68701</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-14T12:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239813#M68702</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;you have not give the address pool?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 12:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239813#M68702</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-14T12:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239816#M68704</link>
      <description>&lt;P&gt;you do not need one for internal host detection.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 12:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239816#M68704</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-14T12:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239817#M68705</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I created an extra internal gateway without tunnel mode.That is what i mean&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 12:31:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239817#M68705</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-14T12:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239826#M68707</link>
      <description>&lt;P&gt;so do you actually use internal gateways. or are you just adding them for internal host detection&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 12:38:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239826#M68707</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-14T12:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239832#M68709</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;just added it for internal host detection&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 13:55:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239832#M68709</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-14T13:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239833#M68710</link>
      <description>&lt;P&gt;you do not need it for internal host detection. remove it.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 14:00:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239833#M68710</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-14T14:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239890#M68722</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The problem is that&lt;/P&gt;&lt;P&gt;In GP application there is an option which says that when the user takes the corporate notebook and go home to connect to home Wi fi and to work he must connect the to GP portal first otherwise you can not get access to anything even Internet from home&lt;/P&gt;&lt;P&gt;When that user comes back to office and connect his Notebook to corporate LAN he get the local network ip address but at the same time tries to connect to GP portal (because of user logon).So it can not connect to outside IP and that is why the user can not get access to anywhere even though it got the local ip address from DHCP&lt;/P&gt;&lt;P&gt;So there must be some mechanism when user connect his laptop to internal lan in the office it must recognize the local network and must connect to other gateway.i guess that must be internal gateway&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 19:10:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239890#M68722</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-14T19:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239897#M68723</link>
      <description>&lt;P&gt;Why cant your users connect to the portal (outside ip) when they are connected to the internal lan. Are you blockng it.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 19:18:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239897#M68723</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-14T19:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239937#M68730</link>
      <description>&lt;P&gt;Please do verify if you have any routing issues/firewall block with in internal network for connecting to your portal public IP. Access to GP portal will work irrespective of client location (either internal network or from internet) until it is reachable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 03:09:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239937#M68730</guid>
      <dc:creator>Rajesh12</dc:creator>
      <dc:date>2018-11-15T03:09:07Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239940#M68732</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/100390"&gt;@Rajesh12&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in order to connect to outside IP i have to configure it as gateway under internal host detection ?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 06:34:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239940#M68732</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-15T06:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239943#M68734</link>
      <description>&lt;P&gt;No, the internal host detection should be something that is on your internal network an resolvable by DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so if you have a domain controller called ad.mynet.com and its address is 10.10.10.1 then put it in the internal host detection settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it does not have to be a server, anything that exists on your lan will suffice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but you need to confirm you can srill see external portal address from lan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you browse to it from your lan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 07:25:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/239943#M68734</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-15T07:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/240039#M68758</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Mike i guess we must configure split DNS in order to connect to the same FQDN whether we are inside the LAN or outside&lt;/P&gt;&lt;P&gt;It is not best practice to connect to your outside ip through your gateway device.&lt;/P&gt;&lt;P&gt;In GP there is internal Gateway.I guess the internal gateway is the method by which you can connect to portal through your internal gateway&lt;/P&gt;</description>
      <pubDate>Thu, 15 Nov 2018 19:37:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/240039#M68758</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-11-15T19:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: To force client to switch to internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/240094#M68773</link>
      <description>&lt;P&gt;When you use internal host detection you do not need to connect to a gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you only connect to the portal to get your portal config..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when you get your portal configuration from your external address the GP clien does a quick test on the settings you have for internal host detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if it detects the internal host Then GP client stops trying to connect and you get a little house in your GP icon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so to confirm.... you do not need internal gateways for internal host detection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you do not need split DNS. &amp;nbsp;What happens when you browse to your external portal address from your lan.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Nov 2018 06:46:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/to-force-client-to-switch-to-internal-network/m-p/240094#M68773</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-16T06:46:56Z</dc:date>
    </item>
  </channel>
</rss>

