Global protect and Outlook 2016

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L1 Bithead

Karthik,

 

Would be interested to see how that option goes when configured under the app agent... did you just put the domain url in there of you had to type in http://<website>

 

For me adding that domain to split tunnel did not resolve the issue, it only worked once i added to pre-logon policies.

 

RJ

View solution in original post

Highlighted

Under the app option, we will be able to override addresses as IP based only (e.g. 1.2.3.4/32, 10.1.2.0/24).

Our initial tests suggested improved connectivity towards MS NLSA DNS resolutions www.msftconnecttest.com, we aren't convinced with the solution yet as extensive users on GP were impacted due to this it has to be tested widely to see as a workable solution.

 

p.s., TAC suggested a list of IP or IP's can be to a certain limit only 32 I reckon I do not have that in writing, unfortunately.

Highlighted
L0 Member

Thank you @rajjair 

 

I've lost count of the number of hours I had sent researching this and trying to understand how I would resolve this issue.  The articles you linked explained the technology well.

 

I too had to create the pre-logon rule allowing access to just that website, after that all works perfectly.  Thanks again for sharing this solution.

 

IT Professional
Highlighted

Well we had to do the same on all our vsys, spinning a new pre rule to permit pre logon GP users to connect back to www.msftconencttest.com over 80 & 443 and it started to work

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!