Will an On-Demand configuration keep GlobalProtect from notifying me that it did not connect?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Will an On-Demand configuration keep GlobalProtect from notifying me that it did not connect?

L1 Bithead

I've deployed GlobalProtect 4.0.3-31 to my lab machines.  When I log in, I get notifications that GlobalProtect is connecting, and then that it is not connected.  I'm not panicked because my portal is not available from my internal network.  Will switching to an On-Demand configuration make these notifications go away?

18 REPLIES 18

@Mick_Ball

I have everyone configured for on demand so they don't automagically connect to the VPN.  I don't believe we have any internal host detection enabled either, I did not configure the box originally and there are still alot of pieces parts I don't understand or know yet

@jdprovine.

 

"and there are still alot of pieces parts I don't understand or know yet"

 

ahhh... welcome to my world....

 

 

@jdprovine, in many ways that is the positive and negative to Palo Alto.  There are many pieces that can be configured and often there is more than one way to put them together.  Thats great for this specific thing or that but at the same time it makes it very difficult to create that standard config that you can just pass off to the next guy.  He probably did something different.

 

@Mick_Ball, the only suggestion I can make on using more than one internal device check is to configure both the IPV4 and IPV6 devices.  It let me configure both but we are not currently using V6 internally so I can not test the functionality for you.

 

Overall we have found the internal vs external configuration works very well (aside from the network swaps previously mentioned).  We have actually found the majority of our GP VPN client problems come from the actual client install itself having problems.  It will either not install properly the first time or something later (we can only assume) messes up the install when it is either installed or updated (new program, updated program, windows update, etc).

 

Brian

@BrianRa

 

Yes the configurations are probably not the same for everyone, but TAC assured me it was 99% unlikely that the configuration on the Zone protection broke my VPN

  • 5160 Views
  • 18 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!