VPN Access

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VPN Access

L4 Transporter

How do you configure the globalprotect VPN's so they won't route on the internal network but will only let users access it from outside the internal network

5 REPLIES 5

Cyber Elite
Cyber Elite

Hello,

Are you referring to preventing internal users from connecting to the external GP gateway so they cannot VPN while on the internal network?

 

Please advise,

Cyber Elite
Cyber Elite

@jdprovine,

Can you fill us in on how your setup looks currently so that we can actually give you the proper recommendation. Depending on how this was configured there are quite a few ways to actually accomplish this.

Its set up with a gateway aand a protal using a loopback interface,tunnel, AD-LDAP authentication and we connect using the global protect client. 

So your internal users are connecting to the public facing IP of your gateway correct? If that is the case then you could just build a security policy to deny the internal zone to your public IP for example set rulebase security rules "Deny Internal Users to GP" from trust source 10.191.0.0/16 to untrust destination 174.175.176.178 action deny log-start no log-end yes

 

Better yet if you have it in it's own zone then simply deny the internal users from your GP zone. As long as you allow traffic from your GP zone to your trust zone then you'll be good to go.

Correct on your description and I will check it out

  • 2147 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!