<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect issue with Enforcer Network Access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-issue-with-enforcer-network-access/m-p/413192#M92935</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We enabled a week ago the feature enforce network access on our environment.&lt;/P&gt;&lt;P&gt;We are using internal host resolution to detect if user is inside or outside corporate network.&lt;/P&gt;&lt;P&gt;In a random way, we're experiencing issue with users worldwide. We have a dns server at each location&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This issue seems to be present only when the user is connected from inside (wifi and wired)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me give you a quick overview :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User is connected to wifi or wired.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client is not detecting as "internal" the network and then it enforces network policy to prevent access if your vpn is not mounted.&lt;/P&gt;&lt;P&gt;We cannot establish vpn from inside network to external gateway (by design and it would not acceptable)&lt;/P&gt;&lt;P&gt;At this time, even if the client is connected to inside, all flow are blocked (due to enforcement, I see it in pangps log) because the tunnel is not established and client not detecting network as internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client has an ip, can successfuly resolve the ptr record that we use in internal check detection but for unknown reason, the issue is still there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any clue would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yoann&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jun 2021 08:55:20 GMT</pubDate>
    <dc:creator>Yoann-Wolf</dc:creator>
    <dc:date>2021-06-15T08:55:20Z</dc:date>
    <item>
      <title>GlobalProtect issue with Enforcer Network Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-issue-with-enforcer-network-access/m-p/413192#M92935</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We enabled a week ago the feature enforce network access on our environment.&lt;/P&gt;&lt;P&gt;We are using internal host resolution to detect if user is inside or outside corporate network.&lt;/P&gt;&lt;P&gt;In a random way, we're experiencing issue with users worldwide. We have a dns server at each location&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This issue seems to be present only when the user is connected from inside (wifi and wired)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me give you a quick overview :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User is connected to wifi or wired.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client is not detecting as "internal" the network and then it enforces network policy to prevent access if your vpn is not mounted.&lt;/P&gt;&lt;P&gt;We cannot establish vpn from inside network to external gateway (by design and it would not acceptable)&lt;/P&gt;&lt;P&gt;At this time, even if the client is connected to inside, all flow are blocked (due to enforcement, I see it in pangps log) because the tunnel is not established and client not detecting network as internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The client has an ip, can successfuly resolve the ptr record that we use in internal check detection but for unknown reason, the issue is still there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any clue would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yoann&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 08:55:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-issue-with-enforcer-network-access/m-p/413192#M92935</guid>
      <dc:creator>Yoann-Wolf</dc:creator>
      <dc:date>2021-06-15T08:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect issue with Enforcer Network Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-issue-with-enforcer-network-access/m-p/413423#M92961</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/180197"&gt;@Yoann-Wolf&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Assuming that you aren't using On-Demand as your connection method correct?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The first few things that I would look at is if the reverse DNS lookup is succeeding in the PanGPS logs, whether the internal host detection hostname matches&amp;nbsp;&lt;EM&gt;exactly&amp;nbsp;&lt;/EM&gt;what has been configured, and if ICMP is allowed to that host.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 21:26:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-issue-with-enforcer-network-access/m-p/413423#M92961</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-06-15T21:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect issue with Enforcer Network Access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-issue-with-enforcer-network-access/m-p/414133#M93053</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank for your reply.&lt;/P&gt;&lt;P&gt;The fqdn/ip configured is exactly the same as what we've configured centrally.&lt;/P&gt;&lt;P&gt;This is not a global issue as not all users are impacted. It's happening at any time, I haven't find the trigger yet but keep analyzing at this time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I ask you why the icmp fact is important ? I thought the process was only relying on dns resolution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : We're running GP 5.1.5.20&lt;/P&gt;&lt;P&gt;Yoann&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 11:48:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-issue-with-enforcer-network-access/m-p/414133#M93053</guid>
      <dc:creator>Yoann-Wolf</dc:creator>
      <dc:date>2021-06-18T11:48:56Z</dc:date>
    </item>
  </channel>
</rss>

