<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent Globalprotect from connecting when user on internal network in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/318502#M81768</link>
    <description>&lt;P&gt;From what I understand, the only thing needed is that internal detection IP and name. I would check and make sure your reverse lookup is working to whatever you have set for DNS for your clients. Make sure it's responding with the hostname you specified in the internal host detection section in your portal configuration. I think I read something about it having to be all lowecase (can't seem to find that info again so it may be irrelevant). The biggest thing I think is that it's a reverse lookup IP&amp;gt;name, so if you don't have a PTR record it's not going to work properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Mar 2020 14:24:29 GMT</pubDate>
    <dc:creator>ZachBiles</dc:creator>
    <dc:date>2020-03-25T14:24:29Z</dc:date>
    <item>
      <title>Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/318469#M81758</link>
      <description>&lt;P&gt;We want to prevent Globalprotect from connecting when user is on the internal network. We have the client set to manual connect/disconnect but users can be stupid and connect anyway.&lt;/P&gt;&lt;P&gt;We don't have an internal gateway, and dont want any ssl tunnel when user is on internal network.&lt;/P&gt;&lt;P&gt;We tried putting in an ip address&amp;nbsp; of a reachable lan server in the "internal host detection" box and left the "internal gateways" list blank but didnt seem to work.&lt;/P&gt;&lt;P&gt;We also tried removing the DNS entry of the gateway from internal DNS zone (we have split-horizon DNS) but that was more trouble than it was worth due to caching of NX records leaving users unable to connect to VPN until zone TTL expiry when they jumped off the LAN network and tried to connect shortly after.&lt;/P&gt;&lt;P&gt;What is the correct way (by correct I mean best practice) to prevent clients from connecting to GP from internal network (keeping in mind we do not have internal GP gateway and do not want any VPN running when users are on LAN)&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 11:56:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/318469#M81758</guid>
      <dc:creator>SteveVernau</dc:creator>
      <dc:date>2020-03-25T11:56:49Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/318502#M81768</link>
      <description>&lt;P&gt;From what I understand, the only thing needed is that internal detection IP and name. I would check and make sure your reverse lookup is working to whatever you have set for DNS for your clients. Make sure it's responding with the hostname you specified in the internal host detection section in your portal configuration. I think I read something about it having to be all lowecase (can't seem to find that info again so it may be irrelevant). The biggest thing I think is that it's a reverse lookup IP&amp;gt;name, so if you don't have a PTR record it's not going to work properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 14:24:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/318502#M81768</guid>
      <dc:creator>ZachBiles</dc:creator>
      <dc:date>2020-03-25T14:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/318538#M81774</link>
      <description>&lt;P&gt;yes as per&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/127359"&gt;@ZachBiles&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;check the GlobalProtect logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is how it looks when working correctly.&amp;nbsp; (Albeit "Always On") in this case...&amp;nbsp; &amp;nbsp; but the process will be similar.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(11593): GetNetworkTypeDS&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(11596): No ipv6 internal host detection.&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(1816): IP 10.250.1.56&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(1835): host prxweb.yourdomain.co.uk&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(1852): DnsQuery returns 0&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(1867): Resolved 56.1.250.10.in-addr.arpa for internal host detection with return value 0&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(1891): The host name is prxweb.yourdomain.co.uk&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(5932): --Set state to Discovery complete&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(9839): SetVpnStatus called with new status=1, Previous Status=1&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(4112): UpdatePrelogonStateForSSO() - User-logon tunnel state = Connected&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(4797): NetworkDiscoverThread: network type is internal.&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Debug(4803): NetworkDiscoverThread: Discover internal network.&lt;/P&gt;&lt;P&gt;(T19360) 03/25/20 16:43:23:581 Info ( 360): Gateway count is 0 for internal network.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 17:09:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/318538#M81774</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-03-25T17:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/344818#M86243</link>
      <description>&lt;P&gt;Has anyone been able to figure this out? We have internal detection working with the PTR record but users can still manually connect to the gateways. Is there a way to prevent the users from connecting to the gateways manually when they are internal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 15:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/344818#M86243</guid>
      <dc:creator>hdauncey</dc:creator>
      <dc:date>2020-08-20T15:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/425107#M94323</link>
      <description>&lt;P&gt;Is this an Always-ON conn? or On-Demand?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal detection doesn't not work with OD&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 12:40:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/425107#M94323</guid>
      <dc:creator>gurjarn</dc:creator>
      <dc:date>2021-08-06T12:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/431381#M95078</link>
      <description>&lt;P&gt;Maybe a simple security rule not allowing this traffic to get out to the gateway from your internal network?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 13:54:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/431381#M95078</guid>
      <dc:creator>ZachBiles</dc:creator>
      <dc:date>2021-09-03T13:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/431541#M95098</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Another thought would be, why disable it? Let the internal clients connect to an internat GP Portal/Gateway so that way you have zero trust between hosts on the LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just a thought, I know there are other factors.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 21:10:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/431541#M95098</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-09-03T21:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent Globalprotect from connecting when user on internal network</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/451315#M101142</link>
      <description>&lt;P&gt;Because when on site it says in the lower right Gateway External-Gateways&lt;BR /&gt;The network connection is unreliable and GlobalProtect reconnected using an... (then it's cut off and not fit on the screen).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 21:17:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/prevent-globalprotect-from-connecting-when-user-on-internal/m-p/451315#M101142</guid>
      <dc:creator>ksauer507</dc:creator>
      <dc:date>2021-12-03T21:17:26Z</dc:date>
    </item>
  </channel>
</rss>

