<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow traffic to specified hosts/networks when Enforce GlobalProtect enable in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/345843#M86399</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to use the feature&amp;nbsp;&lt;STRONG&gt;Enforce GlobalProtect for Network Access.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Outside the company, users must use Global Protect to network access, but when users are on the company site, they should be able to access the local company network. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For that I use the parameter "Allow traffic to specified hosts/networks when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established" with my specific local network address. its works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But the local company network also allows internet access for users, but this remains blocked because only the local network is authorized in exclusion.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this possible to fix this way ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your help&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2020 12:28:33 GMT</pubDate>
    <dc:creator>fd9999</dc:creator>
    <dc:date>2020-08-28T12:28:33Z</dc:date>
    <item>
      <title>Allow traffic to specified hosts/networks when Enforce GlobalProtect enable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/345843#M86399</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to use the feature&amp;nbsp;&lt;STRONG&gt;Enforce GlobalProtect for Network Access.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Outside the company, users must use Global Protect to network access, but when users are on the company site, they should be able to access the local company network. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;For that I use the parameter "Allow traffic to specified hosts/networks when Enforce GlobalProtect Connection for Network Access is enabled and GlobalProtect Connection is not established" with my specific local network address. its works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But the local company network also allows internet access for users, but this remains blocked because only the local network is authorized in exclusion.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is this possible to fix this way ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your help&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 12:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/345843#M86399</guid>
      <dc:creator>fd9999</dc:creator>
      <dc:date>2020-08-28T12:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect en</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/345897#M86412</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When the users are on the company network, are they are required to VPN in also? I would start with the Logs to see why the traffic is getting blocked. Might need additional policies.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 20:53:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/345897#M86412</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-08-28T20:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect en</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/346107#M86451</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153554"&gt;@fd9999&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The best solution will be to create an internal gateway , so the GP agent can connect to internal gateway and users will get internet through the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH1CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH1CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ram&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 20:42:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/346107#M86451</guid>
      <dc:creator>RamprakashRT</dc:creator>
      <dc:date>2020-08-31T20:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect en</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/346236#M86483</link>
      <description>&lt;P&gt;No, on the company network, users shouldn't use GP. They have local network access and internet throught firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When GP is disconnected, traffic is getting blocked by GP restriction, so i can only use my local network (cause i declared my network in exclusion)&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 12:10:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/346236#M86483</guid>
      <dc:creator>fd9999</dc:creator>
      <dc:date>2020-09-01T12:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Allow traffic to specified hosts/networks when Enforce GlobalProtect en</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/346240#M86485</link>
      <description>&lt;P&gt;We would like to use VPN only outside the company.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Sep 2020 12:20:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-traffic-to-specified-hosts-networks-when-enforce/m-p/346240#M86485</guid>
      <dc:creator>fd9999</dc:creator>
      <dc:date>2020-09-01T12:20:24Z</dc:date>
    </item>
  </channel>
</rss>

