<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333629#M84235</link>
    <description>&lt;P&gt;K a chopped file and some notes below...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;function FindProxyForURL(url, host) {&lt;BR /&gt;var proxy="PROXY 1.2.3.9:9354";&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;if (isInNet(host, "x.x.x.x", "255.255.248.0") ||&lt;BR /&gt;isInNet(host, "x.x.x.x", "255.255.255.192") ||&lt;BR /&gt;isInNet(host, "x.x.x.x", "255.255.255.128") ||&lt;BR /&gt;isInNet(host, "x.x.x.x", "255.255.255.224") ||&lt;BR /&gt;shExpMatch(host, "*.manage.microsoft.com") ||&lt;BR /&gt;isInNet(dnsResolve("any.internal.web.server"), "10.250.1.56", "255.255.255.255")) {&lt;BR /&gt;return "DIRECT";&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;return proxy&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we do not use proxy for GP when connected so proxy address is duff....&amp;nbsp; if you have internal proxies then can include.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the x.x.x.x subnets are all of our ISP addresses as we use most of these for portals, gateways and some basic web help files ava to the outside world.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the dns resolve, when connected is a good way of removing proxy settings but you may prefer to use subnets as in your example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit. and the match host is for InTune as this is how we manage IOS profiles.&amp;nbsp; so if it blows up we can still download a new profile to device,&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2020 13:16:37 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2020-06-16T13:16:37Z</dc:date>
    <item>
      <title>How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236117#M67685</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i'm currently testing the GlobalProtect App 5 with iOS Deviecs and Airwatch MDM. Everything works great, but it seems like that it isn't important which setting i've selected in the Portal &amp;gt; Agent &amp;gt; App (Settings).&lt;STRONG&gt; I've tried to enforce GlobalProtect for Network Access on iPhone&lt;/STRONG&gt; but i can still deselect "connect on demand", so it is possible to access the Internet without GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any Ideas? Does the Agent Settings effect? Anything else to configure espacially in AirWatch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jochen&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 06:46:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236117#M67685</guid>
      <dc:creator>Jochen.Reinecke</dc:creator>
      <dc:date>2018-10-19T06:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236139#M67690</link>
      <description>&lt;P&gt;since day one of GP on IOS&amp;nbsp; it has not been possible to force GP...&lt;/P&gt;&lt;P&gt;the user always has the option to disable VPN in the settings menu regardless of app settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I use a global proxy to prevent internet browsing when not connected via GP as never found any other way of enforcing this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 09:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236139#M67690</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-10-19T09:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236263#M67712</link>
      <description>&lt;P&gt;Hello Mick,&lt;/P&gt;&lt;P&gt;Would be able to get into a bit more detail on the global proxy and how you force mobile devices to use it? I would like to hear how others are solving this solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 18:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236263#M67712</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-10-19T18:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236327#M67732</link>
      <description>Of course Mr Klier.&lt;BR /&gt;In brief...&lt;BR /&gt;we have just under 2k users with ipads. These are managed via mdm.&lt;BR /&gt;The global proxy is set via mdm so users cannot change or remove it&lt;BR /&gt;It points to a proxy.pac file on tinternet.&lt;BR /&gt;The proxy server is 1.2.3.4, this obviously does not exist so any web browsing fails with proxy error...&lt;BR /&gt;However....&lt;BR /&gt;There are exceptions in the pac file that allows direct access (no proxy) to our portals and gateways.&lt;BR /&gt;&lt;BR /&gt;This allows GlobalProtect to bypass global proxy settings and connect as normal..&lt;BR /&gt;&lt;BR /&gt;There is another statement within the pac file that says “ if connected to corporate network then go direct” (no proxy) so users browse as normal when connected via our internal to external firewalls.&lt;BR /&gt;&lt;BR /&gt;This for some reason also works with captive portal wifi connections... it does something clever to allow captive portal auth prior to applying global proxy. Nothing to do with the pac file, its just an ios thing...&lt;BR /&gt;&lt;BR /&gt;Not everyones cup of tea but has proved a winner for us over many years....&lt;BR /&gt;&lt;BR /&gt;Happy to provide an example pac file if needs be...&lt;BR /&gt;&lt;BR /&gt;We also use similar for windoze devices as the force global protect option just does not play with our users and crams helpdesk with calls regarding the captive portal timeout thingy...&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sat, 20 Oct 2018 09:46:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236327#M67732</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-10-20T09:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236328#M67733</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Nice solution for the iOS devices. Need to keep that in mind &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am also interested in the way you solved the problem on windows. The way I used here is set the captive portal timeout to 1 hour and use simple http websites as default websites in the users browsers. The notifications of global protect are not very useful (not to say useless), but this way the user only has to open the browser to be redirected to whatever captive portal there is. This http website does nothing else than redirecting to the https company website, but as it is http it does not break the captive portal redirect.&lt;/P&gt;</description>
      <pubDate>Sat, 20 Oct 2018 13:00:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236328#M67733</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-10-20T13:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236443#M67760</link>
      <description>&lt;P&gt;Hey MickBall,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nice solution, a little&amp;nbsp;&lt;SPAN class="short_text"&gt;&lt;SPAN&gt;through the breast into the eye&lt;/SPAN&gt;&lt;/SPAN&gt; but still fine! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe the option in the agent settings could be extended with "(Windows only)" as some other options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jochen&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 09:16:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236443#M67760</guid>
      <dc:creator>Jochen.Reinecke</dc:creator>
      <dc:date>2018-10-22T09:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236448#M67762</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;,I'm liking the default default web page to invoke captive portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have an icon on the desktop called "Connect to Public WiFi".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this also points to our corp website and invokes the same response pages but it disables the proxy settings for 3 mins...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;eva iva are workable solutions but bear in mind that we were using this way before the option of "GP enforce traffic" was ever introduced and have been using pac files long before the Juniper boxes were re-badged...&amp;nbsp; lol....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... just sticking to what works for us just now but if needs be i would certainly move towards your solution.. (not sure about the 1 hour timeout)...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 09:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236448#M67762</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-10-22T09:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone with GP 5.0 App</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236450#M67763</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/40659"&gt;@Jochen.Reinecke&lt;/a&gt;, yes understood but please note my previous response to Mr Remo...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have been using pac files to restrict laptops since day one of VPN and the GP force traffic option has not been around very long.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so as it was already there then its easier to continue as is...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if we did not have pac files in place then the &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp; solution would certainly suffice...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think most of the App settings should contain (Windows Only (depending of course what mood your IPad is in and which motion was used when removing it from your laptop bag))&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Laters...&lt;/P&gt;</description>
      <pubDate>Mon, 22 Oct 2018 09:52:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/236450#M67763</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-10-22T09:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333472#M84211</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are beginning to roll out GP for iOS devices and having an issue with this same topic.&amp;nbsp; Are you still using the proxy.pac file?&amp;nbsp; If so, can you share some details on how to do it?&amp;nbsp; I'm not sure where to host this or what format for the file to be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 17:04:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333472#M84211</guid>
      <dc:creator>brianjreed</dc:creator>
      <dc:date>2020-06-15T17:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333476#M84213</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/104856"&gt;@brianjreed&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;of course ... no problemo....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the pac file needs to be available to ipads outside the vpn tunnel. &amp;nbsp; So a website somewhere...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the pac file just says,,,, in laymans terms,,, &amp;nbsp; Send all traffic to a duff proxy apart from the global protect connection traffic, and if connected to the private network, cancel the duff proxy...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this blocks all browser traffic by sending it to a proxy that does not exist. But it allows gp connection. When gp is connected it drops the proxy settings so all traffic goes down tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it reverts if tunnel fails. You actually dont need a proxy, just a pac file of a few lines of text.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 17:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333476#M84213</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-15T17:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333492#M84214</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; Any chance you could share your (or a sample) pac file?&amp;nbsp; I can successfully block all traffic with the pac but cannot allow any specific websites/urls/domains.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 18:10:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333492#M84214</guid>
      <dc:creator>brianjreed</dc:creator>
      <dc:date>2020-06-15T18:10:36Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333497#M84215</link>
      <description>&lt;P&gt;Yes of course but it may be easier understood if you postvwhat you have, and inwill edit for the purpose, youbwill then better understand the process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if not then i will just send an example...&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 18:28:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333497#M84215</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-15T18:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333498#M84216</link>
      <description>&lt;P&gt;Sure, I've tried a few samples I've found online.&amp;nbsp; Really I just want to allow "direct" to my GW (filter.tesd.net) and push all to a fake proxy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;function FindProxyForURL(url, host) {&lt;BR /&gt;&lt;BR /&gt;// If the hostname matches, send direct.&lt;BR /&gt;if (dnsDomainIs(host, "filter.tesd.net") ||&lt;BR /&gt;shExpMatch(host, "(*.tesd.net|tesd.net)"))&lt;BR /&gt;return "DIRECT";&lt;/P&gt;&lt;P&gt;// If the requested website is hosted within the internal network, send direct.&lt;BR /&gt;if (isPlainHostName(host) ||&lt;BR /&gt;shExpMatch(host, "*.local*") ||&lt;BR /&gt;isInNet(dnsResolve(host), "10.0.0.0", "255.0.0.0") ||&lt;BR /&gt;isInNet(dnsResolve(host), "172.16.0.0", "255.240.0.0") ||&lt;BR /&gt;isInNet(dnsResolve(host), "192.168.0.0", "255.255.0.0")&lt;BR /&gt;return "DIRECT";&lt;/P&gt;&lt;P&gt;// DEFAULT RULE: All other traffic, use below proxies, in fail-over order.&lt;BR /&gt;return "PROXY 4.5.6.7:8080; PROXY 7.8.9.10:8080";&lt;BR /&gt;&lt;BR /&gt;}&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 18:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333498#M84216</guid>
      <dc:creator>brianjreed</dc:creator>
      <dc:date>2020-06-15T18:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333629#M84235</link>
      <description>&lt;P&gt;K a chopped file and some notes below...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;function FindProxyForURL(url, host) {&lt;BR /&gt;var proxy="PROXY 1.2.3.9:9354";&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;if (isInNet(host, "x.x.x.x", "255.255.248.0") ||&lt;BR /&gt;isInNet(host, "x.x.x.x", "255.255.255.192") ||&lt;BR /&gt;isInNet(host, "x.x.x.x", "255.255.255.128") ||&lt;BR /&gt;isInNet(host, "x.x.x.x", "255.255.255.224") ||&lt;BR /&gt;shExpMatch(host, "*.manage.microsoft.com") ||&lt;BR /&gt;isInNet(dnsResolve("any.internal.web.server"), "10.250.1.56", "255.255.255.255")) {&lt;BR /&gt;return "DIRECT";&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;return proxy&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we do not use proxy for GP when connected so proxy address is duff....&amp;nbsp; if you have internal proxies then can include.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the x.x.x.x subnets are all of our ISP addresses as we use most of these for portals, gateways and some basic web help files ava to the outside world.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the dns resolve, when connected is a good way of removing proxy settings but you may prefer to use subnets as in your example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit. and the match host is for InTune as this is how we manage IOS profiles.&amp;nbsp; so if it blows up we can still download a new profile to device,&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2020 13:16:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333629#M84235</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-06-16T13:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333866#M84266</link>
      <description>&lt;P&gt;Thank you so much!&amp;nbsp; Exactly what I needed.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 17:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/333866#M84266</guid>
      <dc:creator>brianjreed</dc:creator>
      <dc:date>2020-06-17T17:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/346828#M86554</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt; Very cool resolution to this problem.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 02:23:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/346828#M86554</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-09-04T02:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/346913#M86561</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to ask, if the file doesn't exist on the internet, how is the IPAD&amp;nbsp; reading that file?&amp;nbsp; Is it locally pushed down somewhere?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 16:09:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/346913#M86561</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-09-04T16:09:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/346914#M86562</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/59122"&gt;@Sec101&lt;/a&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;for ios it needs to be on interweb.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http:\\yourserver.com\nameofpacfile.pac&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on windoze you can use local file location, but that may have recently changed but you would be better using file on web as any change will be picked up by all clients immediately.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hth.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;mick.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Sep 2020 16:19:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/346914#M86562</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-09-04T16:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/352862#M87246</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When your ipads are internal, are you tunneling those devices?&amp;nbsp; &amp;nbsp;I'm having some issues getting user-id to populate usernames if the ipad is internal only without a tunnel.&amp;nbsp; &amp;nbsp;The tunnel works as expected though...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 00:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/352862#M87246</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-09-30T00:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to enforce GlobalProtect Connection for Network Access on iPhone wi</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/352882#M87248</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/157358"&gt;@Sec101&lt;/a&gt;&amp;nbsp;. Hi.&lt;/P&gt;&lt;P&gt;they are never internal. &amp;nbsp; Our office based users (ipad) just connect to our public wifi service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The outgoing wifi palo has a link to GP palo save hairpin/trombone across isp. &amp;nbsp;Sorry not much help for you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are some options for ios to auth on a domain for file share but was not for us.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-enforce-globalprotect-connection-for-network-access-on/m-p/352882#M87248</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-09-30T05:04:15Z</dc:date>
    </item>
  </channel>
</rss>

