GlobalProtect Remote User VPN Connection Issues

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L1 Bithead

GlobalProtect Remote User VPN Connection Issues

 

Hi All,

 

We deployed PA3020 firewall to our production. We have given vpn to client side and it working fine but the problem is they are no any disconnection button to disconnect from vpn client.

 

test.JPG

 

Please advice me

Thanks.

 

Highlighted
L4 Transporter

Hi Lakshithas,

 

You can disconnect by disabling the app. If you're using Windows, open the hidden icons on the task bar and right click the GP icon, select disable.

 

disableGP.png

 

hope this helps,

Ben

Highlighted
L7 Applicator

You'll want to change the connect method to 'on demand' rather than 'always on' which doesn't allow disconnecting

 

 

2016-12-02_11-33-05.png

Tom Piens - PANgurus.com
New to PAN-OS or getting ready to take the PCNSE? check out amazon.com/dp/1789956374
Highlighted
Cyber Elite

You might want to look at your GlobalProtect config as a whole and decide which path makes more sense for your business.

Always On connections are really good at making sure that your corporate issued devices aren't connecting to joe's wireless and provides a good level of protection. If they aren't using issued devices to connect then I would personally still use an Always On connection and setup slit-tunnel so that only the corporate traffic is going through GP. This provides them a path to the resources that they need access to but will just shove everything else out through the internet.

 

On-Demand connections I would really only recommend if this is users connecting in from a home connection from their desktop or laptop. This allows them to connect to everything but also allows them to turn it off when they don't need it; this usually provides a little more piece of mind over the company being able to montior all of their network traffic. 

Highlighted
L1 Bithead

Hi all,

 

Thanks guys.

I will do the needful GlobalProtect configuration.

Again thanks for the prompt support.

 

Friends I need to clarify one thing. Will PA release cilentless vpn near future? We have configured clientless  VPN with ASA. But still we are unable to provide that with PA3020. Any suggestions??

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!