<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299701#M78397</link>
    <description>&lt;P&gt;Oh, great find!&amp;nbsp; Maybe I'll try this out w/ the beta client.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2019 14:22:36 GMT</pubDate>
    <dc:creator>OwenFuller</dc:creator>
    <dc:date>2019-11-20T14:22:36Z</dc:date>
    <item>
      <title>Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/293186#M77520</link>
      <description>&lt;P&gt;We've been troubleshooting some issues encountered when using the "Enforce GlobalProtect Connection for Network Access" option in our portal agent configuration.&amp;nbsp; Our TAC engineer mentioned that he had seen a setting called "Allow traffic to specified hosts/networks when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established" in 8.1, but didn't see it in 9.0.&amp;nbsp; (The setting should allow certain hosts to be exempted from the enforced use of GP.)&amp;nbsp; However, today I noticed it in the portal config for the first time (we just updated to 9.0.4 last week).&amp;nbsp; I tried putting in an IP address for the parameter value, and also using the whole subnet w/ mask.&amp;nbsp; However, it didn't work to allow access to those hosts.&lt;BR /&gt;&lt;BR /&gt;I can't seem to find documentation for this parameter anywhere!&amp;nbsp; I've looked in the offline help in Panorama, v 8.1 and v 9.0 GlobalProtect administrator's guide, searching on this forum, and searching Google in general.&amp;nbsp; The TAC engineer didn't even have documentation for this.&amp;nbsp; Does anyone know the syntax, or how to get it to work?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 21:15:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/293186#M77520</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-10-16T21:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295298#M77812</link>
      <description>&lt;P&gt;Hello there&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I am trying&amp;nbsp; to work out and understand the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see the option for &lt;STRONG&gt;Enforce GlobalProtect Connection for Network Access&lt;/STRONG&gt;, and it is a yes or no.&lt;/P&gt;&lt;P&gt;Yes means that NO network traffic can pass without the machine being connected via GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I&amp;nbsp; too, looked at the 8.1 GP admin guide and do not see an exception to the &lt;SPAN class=""&gt;&lt;SPAN class="highlight"&gt;Enforce&lt;/SPAN&gt; GlobalProtect &lt;/SPAN&gt;Connection setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, perhaps the TAC engineer was incorrect in his memory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For now, I would create a configuration that specifically excludes that particular computer from needing to connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will this help?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 22:01:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295298#M77812</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-10-30T22:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295334#M77818</link>
      <description>&lt;P&gt;Steve, we are excluding this setting across the board right now, because we unfortunately have a large number of machines which would need an exception.&amp;nbsp; We're still doing Always On mode, and the login dialog box is pretty "in your face" annoying until you sign in, which should help encourage users to authenticate.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here's a screenshot of the parameter.&amp;nbsp; Want to know the dumber thing?&amp;nbsp; Once you've set a value, you can't change it back to blank!&amp;nbsp; The window won't let you save it anymore!&amp;nbsp; My case engineer escalated it a week ago, and still has no idea how to configure it.&amp;nbsp; It seems to be some half baked "feature" that does nothing at this point.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-10-30 22_08_52-PanoramaPWk01.png" style="width: 396px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22005i271A852E0C585C2B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-10-30 22_08_52-PanoramaPWk01.png" alt="2019-10-30 22_08_52-PanoramaPWk01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-10-30 22_12_02-PanoramaPWk01.png" style="width: 584px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/22006i32BB29F417C1335D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-10-30 22_12_02-PanoramaPWk01.png" alt="2019-10-30 22_12_02-PanoramaPWk01.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 03:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295334#M77818</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-10-31T03:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295437#M77828</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107710"&gt;@OwenFuller&lt;/a&gt;&amp;nbsp;Welp, you weren't lying.&amp;nbsp; I set that up on my test palo and was unable to change it back to blank.&amp;nbsp; Well, I was but only because a saved a snapshot first.&amp;nbsp; Otherwise I got the same error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like a bug that needs fixed.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 14:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295437#M77828</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-10-31T14:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295450#M77834</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107987"&gt;@Shawverr&lt;/a&gt;&amp;nbsp;wrote:&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looks like a bug that needs fixed.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Well, once TAC acknowledges that the "feature" even exists, then maybe we can get a bugfix submitted! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 14:47:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295450#M77834</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-10-31T14:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295454#M77836</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/107710"&gt;@OwenFuller&lt;/a&gt;&amp;nbsp;LOL!!!!&amp;nbsp; That's why I decided to post, not because I could help, but I could at least confirm the issue.&amp;nbsp; Hopefully that helps.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2019 14:53:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/295454#M77836</guid>
      <dc:creator>Shawverr</dc:creator>
      <dc:date>2019-10-31T14:53:09Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/297044#M78018</link>
      <description>&lt;P&gt;value must contain the mask i.e 8.8.8.8/32 or 10.0.0.0/8&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 14:07:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/297044#M78018</guid>
      <dc:creator>RichColeman</dc:creator>
      <dc:date>2019-11-07T14:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299469#M78363</link>
      <description>&lt;P&gt;For anyone following, or who finds this in the future, here's the latest from TAC:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Seems like the issue with the enforcer exception list will be fixed 8.1.14 and 9.0.8. there are no release dates for these firmware yet, so it might be a while.&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 19 Nov 2019 16:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299469#M78363</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-11-19T16:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299471#M78365</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23197"&gt;@RichColeman&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;value must contain the mask i.e 8.8.8.8/32 or 10.0.0.0/8&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Thanks for the tip, Rich.&amp;nbsp; We'll give this a try.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2019 16:37:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299471#M78365</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-11-19T16:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299672#M78393</link>
      <description>&lt;P&gt;I've had confirmation from TAC this option also "currently" only works with GP client version 5.1.0 (which is in beta), my portal is running 8.1.4 and as soon as I upgraded to 5.1.0 the option (after configuring) worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Think there's a disconnect, I will assume the fix will remove the need for the client to be on an un-released version&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 09:53:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299672#M78393</guid>
      <dc:creator>RichColeman</dc:creator>
      <dc:date>2019-11-20T09:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299688#M78395</link>
      <description>&lt;P&gt;Thanks for updating with this information.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 11:35:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299688#M78395</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-20T11:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299701#M78397</link>
      <description>&lt;P&gt;Oh, great find!&amp;nbsp; Maybe I'll try this out w/ the beta client.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2019 14:22:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/299701#M78397</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-11-20T14:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/300275#M78472</link>
      <description>&lt;P&gt;This feature will be supported with GP Agent 5.1.0. Existing agent is not supporting this option.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 17:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/300275#M78472</guid>
      <dc:creator>cyurekli</dc:creator>
      <dc:date>2019-11-22T17:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/300515#M78518</link>
      <description>&lt;P&gt;Turns out there are a number of features running in 8.1 which isn't available until your running client version 5.1 would be handy of Plao documented them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've reached out to my TAM a requested this info, once I have I'll post it on here.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 08:16:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/300515#M78518</guid>
      <dc:creator>RichColeman</dc:creator>
      <dc:date>2019-11-25T08:16:28Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/300830#M78579</link>
      <description>&lt;P&gt;I have confirmed that the exception list works when using GlobalProtect agent 5.1 beta in accordance with information in the release notes, and the info from&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/78927"&gt;@cyurekli&lt;/a&gt;.&amp;nbsp;With a little experimenting, I was able to determine the following details, which I'm sharing since documentation is still scant:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A single address in the exception list can be entered with no subnet mask (e.g. 192.168.223.1)&lt;/LI&gt;&lt;LI&gt;Multiple addresses must be entered with a mask (thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/23197"&gt;@RichColeman&lt;/a&gt;), and separated by a comma (e.g. 192.168.223.1/32,10.0.0.1/32)&lt;/LI&gt;&lt;LI&gt;Once the GP client connects to the gateway, access to the exception list addresses no longer applies&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;As a reminder, my TAC engineer also had this to say:&lt;BR /&gt;&lt;EM&gt;Seems like the issue with the enforcer exception list will be fixed 8.1.14 and 9.0.8. there are no release dates for these firmware yet, so it might be a while.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;Thank you all for the help!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 19:35:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/300830#M78579</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2019-11-26T19:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  f</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/327789#M83393</link>
      <description>&lt;P&gt;0.0.0.0/0 is too large and it is the opposite of GP enforcement. I would expect that 0.0.0.0/0 is ignored. Can you try with a smaller subnet?&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 17:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/327789#M83393</guid>
      <dc:creator>cyurekli</dc:creator>
      <dc:date>2020-05-13T17:27:28Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  f</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/327948#M83407</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/41917"&gt;@mdensley&lt;/a&gt;&amp;nbsp;I'm not sure exactly what you're trying to accomplish.&amp;nbsp; Could you elaborate?&lt;BR /&gt;&lt;BR /&gt;If you don't actually want to enforce GP for network access, I'd disable that option in your portal config.&amp;nbsp; The "Allow traffic to specified hosts/networks when Enforce GlobalProtect Connection for Network Access and GlobalProtect Connection is not established" is really intended for making limited exceptions when you want to lock down all network access if you user isn't on VPN.&amp;nbsp; If your main goal is just to notify users when they've lost their VPN connection due to a poor network connection for example, I'd suggest a different approach.&amp;nbsp; You might want to start with enabling cookies on your portal/gateway which allow the user to reconnect withing a specified amount of time (whatever makes sense with your security/operational requirements) without re-authenticating.&amp;nbsp; Then, use the "Automatic Restoration of VPN Connection Timeout (min)" and the "Wait Time Between VPN Connection Restore Attempts (sec)" settings to enable GlobalProtect to automatically try to reconnect if it briefly loses connection.&amp;nbsp; This is seamless to your end user, and requires no prompt or interaction.&amp;nbsp; If you want the VPN to generally be connected for the user all the time, but not "enforced" for network access, then you can set the "Connect Method" to User-Logon (Always On).&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 14:50:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/327948#M83407</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-05-14T14:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  f</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/331222#M83894</link>
      <description>&lt;P&gt;I think the closest you will get is doing the cookies with the auto-reconnect option. I believe this should still work just fine. It’s not going to do quite what you want in terms of a specific message, but it should still pop up the GP window from the system tray as it tries to reestablish the connection. &lt;SPAN&gt;Beyond that, you might be right to go the feature request route.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 22:55:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/331222#M83894</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-06-02T22:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  f</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/336361#M84723</link>
      <description>&lt;P&gt;If you fill in the FQDN area and then delete the value, the firewall will complain too.&amp;nbsp; &amp;nbsp;Seems like either one of these fields, once completed, is enough to make you have to trash your Agent config for that entry, or force you to enter a value in it.&amp;nbsp; &amp;nbsp;This should be fixed.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 18:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/336361#M84723</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-07-01T18:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect  for Network Access Enabled</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/406564#M92120</link>
      <description>&lt;P&gt;This issue is still with GP Agent 5.1.x&lt;/P&gt;</description>
      <pubDate>Thu, 13 May 2021 14:52:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/406564#M92120</guid>
      <dc:creator>DavidMaas1</dc:creator>
      <dc:date>2021-05-13T14:52:57Z</dc:date>
    </item>
  </channel>
</rss>

