- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-10-2018 10:40 AM
Hello,
I am looking to configure an always-on VPN with full tunnel access and enable"Enforce Global protect for Network access".
This basically means that users have to connect GP portal to access network when logging in to their machine when off-prem. Giving us the ability to filter the traffic 24x7 even when off-prem. But, I am now facing a challenge where I need to have them connected to wired network when internal and donot want them to intiate vpn tunnel.
I'd gone through numerous internal host detection docs but all say that if reverse dns is successful,it will try to connect to Internal gateway and then external. But I need a scenario where it has to stop trying VPN process when connected to LAN.
Please provide me your inputs on thisissue.
TIA
07-10-2018 11:08 AM
07-10-2018 01:09 PM - edited 07-10-2018 01:09 PM
@welly_59 Thank you so much for the quick response. How does an agent lookup the hostname& IP? From all the docs, it seems like the IP is reverse-DNS queried for the hostname. Is there any way I can make the agent to do the other way around meaning Hostname should be resolved to specific IP? That way I can forge the response with firewall sinkhole capability and make only specific zone/traffic to be considered as internal.
Apologies If my question seem unclear.
07-10-2018 01:54 PM
Internal Host Detection relies soly on a reverse DNS lookup for the internal host. If the agent is unable to find the internal host the agent assumes that it's outside the network and establishes a tunnel to the external gateway. There isn't a way to modify this behavior.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!