refresh connection option in GP agent allowing users to disconnect GP

Reply
Highlighted
L3 Networker

refresh connection option in GP agent allowing users to disconnect GP

We disallowed users to disable global protect app in Portal > app configuration setting , but still due to refresh connection option user able to disconnect GP and using local internet for browsing.

We don't want to disable GP icon from system tray due to password change policy.

Also enforce global protect for network resource option in app setting, didn't work properly.

Please suggest any alternative solution in this case ?

Highlighted
L2 Linker

Hello,

 

  • Network Enforcement should be on Portal Configuration for all users, 
    • You can verify in registry "Computer\HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto Networks\GlobalProtect\Settings" you should see a "enforce-globalprotect" entry with value "yes".
      • This Registry key can be deployable via Group Policy Object.
  • On Gateway Config;
    • "0.0.0.0/0" should be used.
    • "No direct access to local network" checkbox should be on.
  • Global Protect client should be on recommended version for all clients. As my info its 5.0.9-15

 

Portal_option.JPG

 

gw_config.JPG

 

 

UP
Cyber Elite

@Deepak_K,

The refresh connection option simply "refreshes" the connection (IE: The user disconnects and reconnects automatically). I'd be curious to know how this is allowing your users to simply ignore the VPN and browse locally if you have configured an always-on VPN connection. By design, that option shouldn't be doing anything that would allow a user to bypass the VPN. 

Highlighted
L3 Networker

refresh connection.PNG

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!