Always-ON VPN in the internal network.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Always-ON VPN in the internal network.

L4 Transporter

Hello,

 

I am looking to configure an always-on VPN with full tunnel access and enable"Enforce Global protect for Network access".

This basically means that users have to connect GP portal to access network when logging in to their machine when off-prem. Giving us the ability to filter the traffic 24x7 even when off-prem. But, I am now facing a challenge where I need to have them connected to wired network when internal and donot want them to intiate vpn tunnel. 

I'd gone through numerous internal host detection docs but all say that if reverse dns is successful,it will try to connect to Internal gateway and then external. But I need a scenario where it has to stop trying  VPN process when connected to LAN.

 

Please provide me your inputs on thisissue.

 

TIA

3 REPLIES 3

L3 Networker
If you do not configure an internal gateway, but enable internal host detection, then it will not connect to the external gateway and it will achieve what you are trying to accomplish

@welly_59 Thank you so much for the quick response. How does an agent lookup the hostname& IP? From all the docs, it seems like the IP is reverse-DNS queried for the hostname. Is there any way I can make the agent to do the other way around meaning Hostname should be resolved to specific IP? That way I can forge the response with firewall sinkhole capability and make only specific zone/traffic to be considered as internal.

Apologies If my question seem unclear. 

@SThatipelly,

Internal Host Detection relies soly on a reverse DNS lookup for the internal host. If the agent is unable to find the internal host the agent assumes that it's outside the network and establishes a tunnel to the external gateway. There isn't a way to modify this behavior. 

  • 2981 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!