<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Gateway communication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-gateway-communication/m-p/253640#M72009</link>
    <description>&lt;P&gt;Strictly speaking, the client doesn't talk to the gateway if you are just using it for authentication. It only communicates with the portal to send HIP data (if licenced and configured) and user credentials. It uses TLS to do so, with whatever auth profile you set on the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But you also say that you are testing 3rd party VPN clients, so it sounds like you&amp;nbsp;&lt;STRONG&gt;are&lt;/STRONG&gt; using a tunnel (SSL-VPN is a tunnel, even if not using IPSec). Only GlobalProtect is supported for native authentication. If you aren't using GlobalProtect, you'll need a captive portal to ensure everyone authenticates.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Mar 2019 20:25:07 GMT</pubDate>
    <dc:creator>gwesson</dc:creator>
    <dc:date>2019-03-13T20:25:07Z</dc:date>
    <item>
      <title>Global Protect Gateway communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-gateway-communication/m-p/253615#M72002</link>
      <description>&lt;P&gt;Does anyone have insights into how often the client will talk to the gateway if used only for user-id and not utilizing a tunnel?&amp;nbsp; I know you can set the portal refresh time, but how often does the client actually talk to the gateway after grabbing credentials of the current user when logged in?&amp;nbsp; I ask, because we are testing some 3rd party VPN clients(NOT GP) in addition to GP for user-id, and seeing some inconsistencies when changing networks wirelessly.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 15:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-gateway-communication/m-p/253615#M72002</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2019-03-13T15:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Gateway communication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-gateway-communication/m-p/253640#M72009</link>
      <description>&lt;P&gt;Strictly speaking, the client doesn't talk to the gateway if you are just using it for authentication. It only communicates with the portal to send HIP data (if licenced and configured) and user credentials. It uses TLS to do so, with whatever auth profile you set on the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But you also say that you are testing 3rd party VPN clients, so it sounds like you&amp;nbsp;&lt;STRONG&gt;are&lt;/STRONG&gt; using a tunnel (SSL-VPN is a tunnel, even if not using IPSec). Only GlobalProtect is supported for native authentication. If you aren't using GlobalProtect, you'll need a captive portal to ensure everyone authenticates.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 20:25:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-gateway-communication/m-p/253640#M72009</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-03-13T20:25:07Z</dc:date>
    </item>
  </channel>
</rss>

