<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect - Windows issues in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329891#M83695</link>
    <description>&lt;P&gt;192.168.1.1 is the ip for the tunnel GP.&lt;/P&gt;&lt;P&gt;Network -&amp;gt; Interfaces-&amp;gt;tunnel.1 (192.168.1.1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we add in PanGP adaprter the gateway the ip_tunnel is working fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why? is there any way to configure the gateway for PanGP adapter from the FW?&lt;/P&gt;</description>
    <pubDate>Tue, 26 May 2020 14:34:29 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2020-05-26T14:34:29Z</dc:date>
    <item>
      <title>Global protect - Windows issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/327876#M83397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having any issue wih globalprotect and several feaures of windows (office store, images word...).&lt;/P&gt;&lt;P&gt;we realised that if we configure de default gateway made by hand in PAnGP interfaces, its working fine. Why is this happening?&lt;/P&gt;&lt;P&gt;Is there any way to add atumacticallyany default gateway in PAnGP interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For Windows store we found this link:&lt;/P&gt;&lt;P&gt;&lt;A href="https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F4537233%2Fmicrosoft-store-not-open-after-domain-joined-computer-connects-vpn&amp;amp;data=02%7C01%7CJesus.CANO%40axians.es%7Cc6a775745c0a4e5cb39908d7e08bf980%7Ccae7d06108f340dd80c33c0b8889224a%7C0%7C0%7C637224764096567849&amp;amp;sdata=5vFu7ZANoIVD8jtYEaNYddth68BLQRZQ9H4SMh2yUbY%3D&amp;amp;reserved=0" target="_blank"&gt;https://support.microsoft.com/en-us/help/4537233/microsoft-store-not-open-after-domain-joined-computer-connects-vpn&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 08:09:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/327876#M83397</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-05-14T08:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect - Windows issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329242#M83603</link>
      <description>&lt;P&gt;Do you have security policies allowing the Internet traffic from the zone your GP tunnel is in to get to the Internet?&amp;nbsp; Do you see any blocks in the monitoring tab?&lt;BR /&gt;&lt;BR /&gt;If the security policy isn't the issue, and you are trying to exclude traffic from the tunnel and go straight to the internet, adjusting the default gateway isn't the best way to go.&amp;nbsp; GP generally (at least the ways I've used it), operates in tunnel mode, and clients get an IP address with a 255.255.255.255 subnet mask, and the interface doesn't have a default gateway.&amp;nbsp; The split tunnel section of your gateway configuration determines what goes down the tunnel, and what doesn't. If you're wanting to exclude certain traffic, you can specify it in the split tunnel exclude section, or alternatively only include certain internal subnets in the split tunnel include section.&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 18:32:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329242#M83603</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-05-21T18:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect - Windows issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329834#M83689</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I mean that we have a GP. Some clients (192.168.1.20-192.168.1.50 range) had connectivity issues dowloading the system center (AV). So we went to PanGPadapter and we dont see any gateway for PanGP adapter. So we tried to add this GP gateway (192.168.1.1), and it worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SO is there any way to assign a gateway for PanGP interface from PA config? hy PanGP doesnt have gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 07:59:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329834#M83689</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-05-26T07:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect - Windows issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329886#M83693</link>
      <description>&lt;P&gt;Is&amp;nbsp;&lt;SPAN&gt;192.168.1.20-192.168.1.50 your client pool for GP?&amp;nbsp; I don't know your topology.&amp;nbsp; What devices is 192.168.1.1?&amp;nbsp; The GP interface doesn't have a gateway because of how it works as a tunnel interface.&amp;nbsp; When you put routes in the split tunnel include section of the gateway config &lt;STRONG&gt;(Network &amp;gt; GlobalProtect &amp;gt; Gateways &amp;gt; &lt;EM&gt;Your Gateway &lt;/EM&gt;&amp;gt; Client Settings &amp;gt;&amp;nbsp;&lt;EM&gt;Your Client Config&amp;nbsp;&lt;/EM&gt;&amp;gt; Split Tunnel)&lt;/STRONG&gt;, these routes get installed in the Windows route table by GP with the GP adapter as the on-link interface.&amp;nbsp; Anything in the Exclude section does not get tunneled.&amp;nbsp; You should be able to verify the routes on a Windows machine by running this command in the command prompt:&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;route print&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 13:58:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329886#M83693</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-05-26T13:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect - Windows issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329891#M83695</link>
      <description>&lt;P&gt;192.168.1.1 is the ip for the tunnel GP.&lt;/P&gt;&lt;P&gt;Network -&amp;gt; Interfaces-&amp;gt;tunnel.1 (192.168.1.1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If we add in PanGP adaprter the gateway the ip_tunnel is working fine&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why? is there any way to configure the gateway for PanGP adapter from the FW?&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 14:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/329891#M83695</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-05-26T14:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect - Windows issues</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/331199#M83889</link>
      <description>&lt;P&gt;I have never configured IP addresses on my GlobalProtect tunnel interfaces.&amp;nbsp; When you specify routes in the Split Tunnel Include section, these will get installed in your computer's route table as "on-link" routes pointing to the IP that your GP interface gets from the pool.&amp;nbsp; It looks something like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="OwenFuller_0-1591130057528.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25976i1FCDE517872B82EC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="OwenFuller_0-1591130057528.png" alt="OwenFuller_0-1591130057528.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this case, I'm tunneling everything (0.0.0.0/0), and my GP interface IP address is 172.X.X.X&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 21:09:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-windows-issues/m-p/331199#M83889</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-06-02T21:09:02Z</dc:date>
    </item>
  </channel>
</rss>

