How to disable Global Protect inside Firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How to disable Global Protect inside Firewall

L1 Bithead

Hi All,

I am looking for a way to have the GP client client NOT connect when I am inside the firewall of at a remote site with a VPN tunnel.  Basically I would like to make a rule that says do not connect when connected to certain subnets.

Is there a way to do that?

Thanks!

1 accepted solution

Accepted Solutions

L5 Sessionator

If you configured internal gateway on the GP client. It will automatically detect you on the internal LAN. and on the GP client it will show up as internal instead of connected. This way it will not create a tunnel for the client.

Some useful docs for Global Protect configuration

https://live.paloaltonetworks.com/docs/DOC-2904

https://live.paloaltonetworks.com/docs/DOC-2020

https://live.paloaltonetworks.com/docs/DOC-3930

Hope this helps.

Thanks

View solution in original post

4 REPLIES 4

L5 Sessionator

So are you looking for a way to block access to the gp gtwy from certain subnets, you can create a rule with the source zone from where the traffic is coming from to the gp ip and set the action to block.

For example if your gp gateway is on the untrust and the subnet is on the trust, you can write a rule from trust to untrust with source ip as ur subnet/dest ip as gp gateway.

Please let me know if this is what your looking for.

L5 Sessionator

If you configured internal gateway on the GP client. It will automatically detect you on the internal LAN. and on the GP client it will show up as internal instead of connected. This way it will not create a tunnel for the client.

Some useful docs for Global Protect configuration

https://live.paloaltonetworks.com/docs/DOC-2904

https://live.paloaltonetworks.com/docs/DOC-2020

https://live.paloaltonetworks.com/docs/DOC-3930

Hope this helps.

Thanks

L1 Bithead

Thanks Mbutt.  I created that internal GW and it took care of the issue!

What settings do you give the inside gateway? I'm confused on how the GP agent "knows" it's on the inside network. Is it based on whether or not the internal gw name resolves to an IP? Or the IP is reachable? Or something else?

  • 1 accepted solution
  • 7033 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!