<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Always On When Coming Into the Office in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/406948#M92173</link>
    <description>&lt;P&gt;In your GP portal configuration you need to use internal host detection. Just add the ip address and host name. But do not add internal gateways. This will check every time the portal connection is made.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 15 May 2021 06:55:48 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-05-15T06:55:48Z</dc:date>
    <item>
      <title>Global Protect Always On When Coming Into the Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/406879#M92172</link>
      <description>&lt;P&gt;I finally got certificate based always on GP VPN working when my laptop is at home.&amp;nbsp;&lt;BR /&gt;It occurred to me that when people go into the office, they'd be on the internal LAN.&lt;BR /&gt;How is that normally handled? Since I currently have an egress separate from the&amp;nbsp;&lt;/P&gt;&lt;P&gt;GP PAN the traffic would hit the same portal as when they're home and noone&lt;/P&gt;&lt;P&gt;would be the wiser. But it would be wasting some firewall circuits and adding&lt;/P&gt;&lt;P&gt;some extra hops. Not a huge deal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How is this typically handled? We have a separate DNS zone internal from external&lt;/P&gt;&lt;P&gt;as most places do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 22:10:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/406879#M92172</guid>
      <dc:creator>MichaelMedwid</dc:creator>
      <dc:date>2021-05-14T22:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Always On When Coming Into the Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/406948#M92173</link>
      <description>&lt;P&gt;In your GP portal configuration you need to use internal host detection. Just add the ip address and host name. But do not add internal gateways. This will check every time the portal connection is made.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 15 May 2021 06:55:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/406948#M92173</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-05-15T06:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Always On When Coming Into the Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/406960#M92174</link>
      <description>&lt;P&gt;Great - thank you Mick.&lt;/P&gt;</description>
      <pubDate>Sat, 15 May 2021 07:35:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/406960#M92174</guid>
      <dc:creator>MichaelMedwid</dc:creator>
      <dc:date>2021-05-15T07:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Always On When Coming Into the Office</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/407490#M92236</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132469"&gt;@MichaelMedwid&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will benefit if you configure internal gateway. The difference between internal and external gateway is that client is not building tunnel to FW and at same time you client still needs to go over the process of authenticating and submitting HIP report (if configured to collect data). The benefit of that is you will still have user-to-ip mapping and HIP checks and you can make your rules for internal users more granular&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 09:02:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-always-on-when-coming-into-the-office/m-p/407490#M92236</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-05-18T09:02:00Z</dc:date>
    </item>
  </channel>
</rss>

