refresh connection option in GP agent allowing users to disconnect GP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

refresh connection option in GP agent allowing users to disconnect GP

L3 Networker

We disallowed users to disable global protect app in Portal > app configuration setting , but still due to refresh connection option user able to disconnect GP and using local internet for browsing.

We don't want to disable GP icon from system tray due to password change policy.

Also enforce global protect for network resource option in app setting, didn't work properly.

Please suggest any alternative solution in this case ?

3 REPLIES 3

L3 Networker

Hello,

 

  • Network Enforcement should be on Portal Configuration for all users, 
    • You can verify in registry "Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings" you should see a "enforce-globalprotect" entry with value "yes".
      • This Registry key can be deployable via Group Policy Object.
  • On Gateway Config;
    • "0.0.0.0/0" should be used.
    • "No direct access to local network" checkbox should be on.
  • Global Protect client should be on recommended version for all clients. As my info its 5.0.9-15

 

Portal_option.JPG

 

gw_config.JPG

 

 

UP

Cyber Elite
Cyber Elite

@Deepak_K,

The refresh connection option simply "refreshes" the connection (IE: The user disconnects and reconnects automatically). I'd be curious to know how this is allowing your users to simply ignore the VPN and browse locally if you have configured an always-on VPN connection. By design, that option shouldn't be doing anything that would allow a user to bypass the VPN. 

  • 5105 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!