GP Always on VPN - Except if on internal LAN?

L3 Networker

GP Always on VPN - Except if on internal LAN?

Is there a way to implement this? I have seen the internal host detection option but as far as I can see that is only to choose whether you connect to an internal or external gateway.

I want all remote site users to go through the Palo Alto, but I can achieve that by routing alone. I dont see what I would be achieving by forcing vpn while on internal lan if all users are being sent to the Palo Alto for internet breakout anyway.

I have an external gateway and users are connecting with on-demand. Just looking for a way that I can move to always on, except while on site
L7 Applicator

Re: GP Always on VPN - Except if on internal LAN?


You were already at the right place of the configuration. With the internal host detection the client first tries to resolve the entered IP address. If the IP address resolves to the configured domainname the the client assumes it is in the internal network. After that the client takes the configured action: if an internal gateway is specified a connection is set up to this internal gateway (normally only for user-id of sending HIP information). If you dont have an internal gateway the client simply doesn't do anything while staying internally.

L3 Networker

Re: GP Always on VPN - Except if on internal LAN?

Ah excellent. So if I enable internal host detection, and do not configure an internal gateway, then it will only connect if external.

That’s just what I was looking for!
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!