How to disable Global Protect inside Firewall

Reply
Highlighted
L1 Bithead

How to disable Global Protect inside Firewall

Hi All,

I am looking for a way to have the GP client client NOT connect when I am inside the firewall of at a remote site with a VPN tunnel.  Basically I would like to make a rule that says do not connect when connected to certain subnets.

Is there a way to do that?

Thanks!


Accepted Solutions
L5 Sessionator

Re: How to disable Global Protect inside Firewall

If you configured internal gateway on the GP client. It will automatically detect you on the internal LAN. and on the GP client it will show up as internal instead of connected. This way it will not create a tunnel for the client.

Some useful docs for Global Protect configuration

https://live.paloaltonetworks.com/docs/DOC-2904

https://live.paloaltonetworks.com/docs/DOC-2020

https://live.paloaltonetworks.com/docs/DOC-3930

Hope this helps.

Thanks

View solution in original post


All Replies
Highlighted
L5 Sessionator

Re: How to disable Global Protect inside Firewall

So are you looking for a way to block access to the gp gtwy from certain subnets, you can create a rule with the source zone from where the traffic is coming from to the gp ip and set the action to block.

For example if your gp gateway is on the untrust and the subnet is on the trust, you can write a rule from trust to untrust with source ip as ur subnet/dest ip as gp gateway.

Please let me know if this is what your looking for.

L5 Sessionator

Re: How to disable Global Protect inside Firewall

If you configured internal gateway on the GP client. It will automatically detect you on the internal LAN. and on the GP client it will show up as internal instead of connected. This way it will not create a tunnel for the client.

Some useful docs for Global Protect configuration

https://live.paloaltonetworks.com/docs/DOC-2904

https://live.paloaltonetworks.com/docs/DOC-2020

https://live.paloaltonetworks.com/docs/DOC-3930

Hope this helps.

Thanks

View solution in original post

Highlighted
L1 Bithead

Re: How to disable Global Protect inside Firewall

Thanks Mbutt.  I created that internal GW and it took care of the issue!

Highlighted
L2 Linker

Re: How to disable Global Protect inside Firewall

What settings do you give the inside gateway? I'm confused on how the GP agent "knows" it's on the inside network. Is it based on whether or not the internal gw name resolves to an IP? Or the IP is reachable? Or something else?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!