- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-31-2018 07:17 AM
I've deployed GlobalProtect 4.0.3-31 to my lab machines. When I log in, I get notifications that GlobalProtect is connecting, and then that it is not connected. I'm not panicked because my portal is not available from my internal network. Will switching to an On-Demand configuration make these notifications go away?
02-02-2018 07:10 AM
I have everyone configured for on demand so they don't automagically connect to the VPN. I don't believe we have any internal host detection enabled either, I did not configure the box originally and there are still alot of pieces parts I don't understand or know yet
02-02-2018 07:16 AM
"and there are still alot of pieces parts I don't understand or know yet"
ahhh... welcome to my world....
02-02-2018 05:32 PM
@jdprovine, in many ways that is the positive and negative to Palo Alto. There are many pieces that can be configured and often there is more than one way to put them together. Thats great for this specific thing or that but at the same time it makes it very difficult to create that standard config that you can just pass off to the next guy. He probably did something different.
@Mick_Ball, the only suggestion I can make on using more than one internal device check is to configure both the IPV4 and IPV6 devices. It let me configure both but we are not currently using V6 internally so I can not test the functionality for you.
Overall we have found the internal vs external configuration works very well (aside from the network swaps previously mentioned). We have actually found the majority of our GP VPN client problems come from the actual client install itself having problems. It will either not install properly the first time or something later (we can only assume) messes up the install when it is either installed or updated (new program, updated program, windows update, etc).
Brian
02-05-2018 05:33 AM
Yes the configurations are probably not the same for everyone, but TAC assured me it was 99% unlikely that the configuration on the Zone protection broke my VPN
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!