<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Internal Host Detection in GlobalProtect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/285199#M76393</link>
    <description>&lt;P&gt;If internal host detection is configured, and not internal portals/gateways are defined, will the GP client simply stop trying to establish vpn?&amp;nbsp; Thats what i'd like to see.&lt;/P&gt;</description>
    <pubDate>Tue, 27 Aug 2019 05:41:41 GMT</pubDate>
    <dc:creator>JimMcGrady</dc:creator>
    <dc:date>2019-08-27T05:41:41Z</dc:date>
    <item>
      <title>Internal Host Detection in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/16935#M12344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am confused with GlobalProtect offical documents.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From GlobalProtect troubleshooting guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Internal Host Detection&lt;/STRONG&gt;&lt;BR /&gt;Internal Host Detection provides hints to GP client to determine quickly if the PC is inside or outside office. &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;If it is not configured, GP client will always try to connect to each internal gateway first&lt;/STRONG&gt;&lt;/SPAN&gt;. If it fails to connect to any internal gateway or if there is no internal gateway defined, it will then attempt to connect to the best external gateway. Admin should try to set internal host detection as it speeds up the tunnel establishment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From Configuring GlobalProtect Tech Note:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Internal Host Detection&lt;/STRONG&gt;: This helps Client determine whether the host is inside or outside the corporate network and then connect to the corresponding Gateway. The DNS name specifies a hostname that only can be reached from internal network and its IP address. The Client performs a reverse lookup on the IP address and if it receives the expected hostname as a response, it will attempt connecting to the Gateways in the internal list. If no response is received that Client will attempt to connect to the external Gateways in the external list&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;If no “internal-host-detection” configuration is provided, Client always connectes to the external Gateways. &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know which one is correct?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 09:37:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/16935#M12344</guid>
      <dc:creator>linusso</dc:creator>
      <dc:date>2012-05-14T09:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/16936#M12345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So looking at the purpose of Internal Host Detection, the Client will try to resolve the host name to the IP provided. If DNS does not resolve, it will quickly assume you are not on an internal network, and try to create a tunnel with the external IP's provided in your configuration.&amp;nbsp; Looking at the Admin guide, we can see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="1261037"&gt;External Gateways&lt;/A&gt;—Specify the list of firewalls the client will try to establish a tunnel with &lt;STRONG&gt;when not on the corporate network.&lt;/STRONG&gt; The client will contact all of the gateways and establish a tunnel with the firewall that provides the fastest response and the lowest priority value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This implies that the sequence will be internal, then external. The internal IP's will time out rather quickly and a tunnel will then be established with the fasted external IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this help?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dez&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 03:08:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/16936#M12345</guid>
      <dc:creator>dlorenzen</dc:creator>
      <dc:date>2012-05-23T03:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/16937#M12346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dez,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer. I understand the function of Internal Host Detection from admin guide. My problem is there is contradiction on GP configuration guide and troubleshooting guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, I have opened a support case and now I can confirmed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. If SSO is selected, Internal Host Detection with be used (by reserve DNS lookup, resolve IP to hostname)&lt;/P&gt;&lt;P&gt;2. If On Demand mode is selected. GP client &lt;SPAN style="font-size: 11pt; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;(start from 1.1.4) will always set its network type to 'External' and connect to external gateway. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;3. From support team: "&lt;SPAN style="font-size: 11pt; font-family: &amp;amp;quot;Calibri&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;"&gt;The statement in GP troubleshooting guide looks incorrect. I have escalated to verify this"&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 03:37:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/16937#M12346</guid>
      <dc:creator>linusso</dc:creator>
      <dc:date>2012-05-23T03:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/285199#M76393</link>
      <description>&lt;P&gt;If internal host detection is configured, and not internal portals/gateways are defined, will the GP client simply stop trying to establish vpn?&amp;nbsp; Thats what i'd like to see.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2019 05:41:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/285199#M76393</guid>
      <dc:creator>JimMcGrady</dc:creator>
      <dc:date>2019-08-27T05:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: Internal Host Detection in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/436227#M96244</link>
      <description>&lt;P&gt;This is incorrect, if you define internal host detection and you have no internal gateway define it will just look for that address to be available and if it is then it will not attempt to connect to external gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 18:46:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/internal-host-detection-in-globalprotect/m-p/436227#M96244</guid>
      <dc:creator>jmora</dc:creator>
      <dc:date>2021-09-23T18:46:16Z</dc:date>
    </item>
  </channel>
</rss>

