<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP prompts for internal gw connectivity in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314359#M81101</link>
    <description>&lt;P&gt;Internal host detection IPv4 is set to an internal on-prem IP and the hostname for it does not publicly resolve, plus internal gateways are configured..&lt;/P&gt;</description>
    <pubDate>Wed, 04 Mar 2020 12:40:36 GMT</pubDate>
    <dc:creator>Arne-VDH</dc:creator>
    <dc:date>2020-03-04T12:40:36Z</dc:date>
    <item>
      <title>GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314332#M81096</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've deployed a GlobalProtect installation solely for the purpose of User-ID. The GP agent connects to the internal portal/GW (one box) upon login with Kerberos SSO. However, when the internal gateway is not reachable (user has no network, user isn't on-prem), the GlobalProtect Agent notifies the user about this (no network / can't reach GW).&amp;nbsp;Does anyone know how I can supress this warning?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GP GW Prompt.png" style="width: 428px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24221iC6D7BA957A752865/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GP GW Prompt.png" alt="GP GW Prompt.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 11:08:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314332#M81096</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2020-03-04T11:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314343#M81099</link>
      <description>&lt;P&gt;Hmm.... i don't use internal gateways but don't you need internal host detection to prevent this from happening.&lt;/P&gt;&lt;P&gt;or have you already set this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="int gateway.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/24222iDBEA4BE9096084D8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="int gateway.jpg" alt="int gateway.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 11:39:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314343#M81099</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-03-04T11:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314359#M81101</link>
      <description>&lt;P&gt;Internal host detection IPv4 is set to an internal on-prem IP and the hostname for it does not publicly resolve, plus internal gateways are configured..&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 12:40:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314359#M81101</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2020-03-04T12:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314362#M81102</link>
      <description>&lt;P&gt;Have you tried making the portal external, the gateway internal with host detection and allowing access to the portal from internal network.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 12:57:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314362#M81102</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-03-04T12:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314363#M81103</link>
      <description>&lt;P&gt;No, if possible we highly prefer not to have the portal externally available.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 13:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314363#M81103</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2020-03-04T13:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314364#M81104</link>
      <description>&lt;P&gt;Sure, i understand, but how is the client going to know about the internal host detection if they cant get to the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Portal info is cached but it does not include internal host detection. I know this much because we use it to prevent users connecting to gateways when on the LAN but if the portal cannot be contacted the internal host detection does not kick in and user attempts to connect to a cached portal.&lt;/P&gt;&lt;P&gt;So...&amp;nbsp; &amp;nbsp;I dont think you have much choice here...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 13:12:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314364#M81104</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-03-04T13:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314369#M81106</link>
      <description>&lt;P&gt;I actually don't mind if it can't get to the portal, I just don't want users to see the message -so it's more, can I suppress the message on the client itself or not?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 13:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314369#M81106</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2020-03-04T13:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314371#M81107</link>
      <description>&lt;P&gt;Yep, got it...&amp;nbsp; &amp;nbsp;it does say that in the first post.&lt;/P&gt;&lt;P&gt;I am not aware of message suppression.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 14:15:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/314371#M81107</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-03-04T14:15:04Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315331#M81247</link>
      <description>&lt;P&gt;I'm not quite sure on this, as I have not tried doing&amp;nbsp;&lt;EM&gt;solely&amp;nbsp;&lt;/EM&gt;an internal gateway.&amp;nbsp; However, why not try configuring the gateway as an internal gateway, and use the internal host detection, and list no external gateways?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 20:25:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315331#M81247</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-09T20:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315340#M81251</link>
      <description>&lt;P&gt;That is pretty much exactly the configuration at the moment.. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 20:59:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315340#M81251</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2020-03-09T20:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315357#M81252</link>
      <description>&lt;P&gt;Gotcha.&amp;nbsp; You could change the connection method to on-demand, but I'm guessing that will mess with things when the users are on network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I know you said you prefer not to run the portal on a public interface, I'll offer this as one option to consider.&amp;nbsp; You could configure the portal w/ a different authentication method (LDAP, local, SAML, whatever), and set a long cookie timeout (365 days for example).&amp;nbsp; This would essentially let your machines authenticate with the portal once, and be done with it for a year (or longer, if you also allow the gateway logins to generate a cookie).&amp;nbsp; If you wish, you could further secure this accdss using a certificate profile, and requiring machines to have a cert trusted by the firewall.&amp;nbsp; Then, you could run your internal gateway on an internal interface w/ the kerberos SSO authentication.&amp;nbsp; Then the machines will only attempt kerberos auth via SSO to the gateway when they detect that they are inside your corporate network using internal host detection.&lt;BR /&gt;&lt;BR /&gt;Sorry, I know that isn't quite what you're looking for, but I don't know of a way to suppress the notifications other than these two suggestions.&amp;nbsp; If GlobalProtect doesn't meet your needs in this area, captive portal might be a good way to capture user-id.&amp;nbsp; We do this for some of our Mac users.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 21:19:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315357#M81252</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-09T21:19:02Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315363#M81254</link>
      <description>&lt;P&gt;Well the whole idea is to keep it transparant and not have users authenticate to anything. I do suppose that if I were to use cookies it wouldn't pick up users logging in or out, and on-demand is exactly what we're trying to avoid (with captive portals on top of the list :-)). The agent should be invisible to the end users, but if no one knows an alternative I'm guessing it will be support to confirm or a feature request...&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 21:54:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315363#M81254</guid>
      <dc:creator>Arne-VDH</dc:creator>
      <dc:date>2020-03-09T21:54:33Z</dc:date>
    </item>
    <item>
      <title>Re: GP prompts for internal gw connectivity</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315461#M81265</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37998"&gt;@Arne-VDH&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Well the whole idea is to keep it transparant and not have users authenticate to anything. I do suppose that if I were to use cookies it wouldn't pick up users logging in or out&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, definitely don't want it more complicated than needing.&amp;nbsp; In my experience, it's not the connection to the portal which registers user-id, but the gateway.&amp;nbsp; If you accepted cookies for portal auth, but only accepted Kerberos SSO for the gateway, I wonder if this would still give you what you need.&amp;nbsp; Again, your deployment is a bit different than the ones I've done, so just trying to throw ideas out there.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 13:49:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-prompts-for-internal-gw-connectivity/m-p/315461#M81265</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-03-10T13:49:23Z</dc:date>
    </item>
  </channel>
</rss>

