GlobalProtect Always on Network Connection Forced

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect Always on Network Connection Forced

L0 Member

We are in the testing phase for GP Always on.  I currently have forced network connection with internal host detection and it is working fine. 

 

I did a quick search and did not find the configuration tweaks that would account for Always On / Forced Connection when the portal is unavailable.

 

Use case...I have a user travelling abroad.  When they are at their destination , they will send me their public ip to whitelist for GlobalProtect access.    If she was in the Always On /Forced Network connection policy...does that mean that her lap would basically be bricked as far as network.  She is in a geo blocked country...so no access to Portal without a whitelist entry on my part.   I am sure there is a configuration combination that would allow for this...I want to make sure that the users' Office 365 apps will at least work so they can communicate even if the GP app cannot reach the portal.

 

Thank you

1 REPLY 1

Cyber Elite
Cyber Elite

@JoeBailey,

Correct. Do you have email hosted on-premise or are you using Exchange Online? You'll want to exclude the FQDNs as specified HERE. If you're using Exchange Online due to the number of dependencies required you'll want to look at Microsoft's 365 lists and select what FQDNs you'll need to allow from HERE.

 

Personally when we encounter these sort of issues when people travel we don't allow them to bring their issued device. Depending on the country we either just send them with an unmanaged device for simple email access, or we send them with a cheaper device that is disposed of after they return.

  • 246 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!