- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-22-2025 09:48 PM
Hi Expert,
I have setup an internal GP GW to get user-id, which works fine. But now the question is how to enforce users to connect to it once in office. On GP portal, I set <Enforce GlobalProtect for user access> to Yes , but it is not working. Tried both
01-23-2025 05:06 PM
Thanks a lot for the reply. So this is internal GW with tunnel mode. And I just need to setup a tunnel interface and if need to configure the ip pool ? Or the client just use the DHCP assigned internal ip address.
01-24-2025 05:12 AM
Create an IP pool and also do the split tunneling including all internal network subnets and fqdn's. This will make GP to only forward office network traffic through it's virtual Network adapter and the rest outside internet traffic will be passed through physical Network adapter.
01-26-2025 06:54 PM - edited 01-26-2025 06:55 PM
I think you referring to Internal host detection where users always connect to the internal gateway when in the office. To achieve this you need a PTR record configured on the firewall that must be resolved for internal users.
Let me know if this is the requirement or if I have misunderstood your query.
01-27-2025 10:56 AM
Hi Arusharma, the internal gw is working fine , but question is how to enforce users to connect to GP internal GW by default when they are in office.
Already opened a TAC case, but suggested to use HIP, I do not think that is related.
01-27-2025 12:47 PM
Hello,
Restrict the default LAN IP that is received by the client to only be able to connect to a few things:
https://skrzsecurity.net/zero-trust#:~:text=get%20to%20it.-,Architecture,-%3A
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!