<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Initial configuration in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247211#M70353</link>
    <description>&lt;P&gt;How are people configuring their PAN for clients to grab the inital GP configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, the laptops are being imaged with Windows 10 and automatically connect to our internal network via certificate based authentication. GP is set to automatically attempt to connect to our outside interface. Once that is done, it grabs the configuration. Next time the users are on site, it detects that the laptop is internal and does not create the tunnel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to configure the PAN so that the laptops can grab the inital configuration?&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jan 2019 19:28:52 GMT</pubDate>
    <dc:creator>meischc</dc:creator>
    <dc:date>2019-01-23T19:28:52Z</dc:date>
    <item>
      <title>GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247211#M70353</link>
      <description>&lt;P&gt;How are people configuring their PAN for clients to grab the inital GP configuration?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, the laptops are being imaged with Windows 10 and automatically connect to our internal network via certificate based authentication. GP is set to automatically attempt to connect to our outside interface. Once that is done, it grabs the configuration. Next time the users are on site, it detects that the laptop is internal and does not create the tunnel.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to configure the PAN so that the laptops can grab the inital configuration?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 19:28:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247211#M70353</guid>
      <dc:creator>meischc</dc:creator>
      <dc:date>2019-01-23T19:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247255#M70362</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/102468"&gt;@meischc&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Are you running your own internal DNS servers? Split DNS would really be your solution for something like this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 01:15:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247255#M70362</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-01-24T01:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247306#M70374</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/102468"&gt;@meischc&lt;/a&gt;, Hi.&lt;/P&gt;&lt;P&gt;I'm not sure what you mean, seems a bit confusing...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your users (after they have connected outside) are able to detect internal host then your external&amp;nbsp;portal address&amp;nbsp;must be visible from your LAN otherwise you would get a portal address error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I say this because I have always assumed that GP needs to connect to the portal prior to internal detection, regardless of how many times they have connected externally, otherwise if you made any changes to the app settings then users would not get this until they connected from outside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyhows... not sure what is different from your setup to mine, it may be that you need to add the reg setting "always on" in your build, or perhaps use group policy to force this reg setting when they first logon.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 08:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247306#M70374</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-24T08:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247391#M70383</link>
      <description>&lt;P&gt;Sorry, let me elaborate. After they grab the correct GP Portal configuration hitting the outside interface, everthing is working as designed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem that I am trying to solve, is getting that GP portal configuration on the laptops, prior to hitting the outside interface. Right now, we have a WiFi hotspot that the desktop folks are using to simulate being on the outside connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to configure an internal gateway or NoNAT so that users can hit the outside interface to grab the portal configuration without having to leave the internal network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you accomplishing this? Or do you just wait for your users to connect from home/outside?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 16:39:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247391#M70383</guid>
      <dc:creator>meischc</dc:creator>
      <dc:date>2019-01-24T16:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247393#M70384</link>
      <description>&lt;P&gt;thanks for the clarification....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OK I understand now what you are describing but I cannot understand why it is not working already...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on any laptop on your network, what happens when you browse to https://your-portal-address&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you get to the page and with certificates it should login and display GP downloads.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;lets start there and progress...&amp;nbsp;&amp;nbsp; else i get confused&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 17:06:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247393#M70384</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-24T17:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247397#M70389</link>
      <description>&lt;P&gt;Sorry i have just realised that it may be working for me because our GP portal is on a different firewall. so we go out of our main firewall to connect to our VPN firewall...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure if NAT will suffice... you may be better off adding a second portal to your config and make it available to your internal interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;stated, use your internal dns to resolve to the internal portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for the confusion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 17:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247397#M70389</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-24T17:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247399#M70390</link>
      <description>&lt;P&gt;or simply add a NAT rule at the top of the NAT policies&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;source= trust&amp;nbsp;, Destination Address="Your-portal-ip-address"&amp;nbsp; Source Translation= None&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think what is happening is that your current traffic is being NAT'd to your external address so the Palo will see your external address trying to talk to your external address, this will cause it's nose to start bleeding...&amp;nbsp; and see this as a LAN attack, so add the NAT rule...&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 18:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247399#M70390</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-24T18:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247403#M70391</link>
      <description>&lt;P&gt;Also.... could you confirm that currently when users connect to the lan after connecting externally that they do get the little house icon.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 18:44:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247403#M70391</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-01-24T18:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect Initial configuration</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247405#M70393</link>
      <description>&lt;P&gt;Yep! They do.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jan 2019 19:02:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-initial-configuration/m-p/247405#M70393</guid>
      <dc:creator>meischc</dc:creator>
      <dc:date>2019-01-24T19:02:08Z</dc:date>
    </item>
  </channel>
</rss>

