how to enforce user to connect to GP internal GW

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

how to enforce user to connect to GP internal GW

L1 Bithead

Hi Expert,

 

I have setup an internal GP GW to get user-id, which works fine. But now the question is how to enforce users to connect to it once in office. On GP portal, I set <Enforce GlobalProtect for user access>  to Yes , but it is not working. Tried both 

 <pre-logon always on> and <user-logon always on>.
Please let me know any way can get it resolved.
6 REPLIES 6

Cyber Elite
Cyber Elite

make sure the internal gateway has tunnel mode enabled, else the agent won't connect to it: 

reaper_0-1737664451172.png

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L1 Bithead

Thanks a lot for the reply. So this is internal GW with tunnel mode. And I just need to setup a tunnel interface and if need to configure the ip pool ? Or the client just use the DHCP assigned internal ip address.

L0 Member

Create an IP pool and also do the split tunneling including all internal network subnets and fqdn's. This will make GP to only forward office network traffic through it's virtual Network adapter and the rest outside internet traffic will be passed through physical Network adapter.

L3 Networker

I think you referring to Internal host detection where users always connect to the internal gateway when in the office. To achieve this you need a PTR record configured on the firewall that must be resolved for internal users.

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-global...

 

Let me know if this is the requirement or if I have misunderstood your query. 

L1 Bithead

Hi Arusharma, the internal gw is working fine , but question is how to enforce users to connect to GP internal GW by default when they are in office. 

Already opened a TAC case, but suggested to use HIP, I do not think that is related.

Cyber Elite
Cyber Elite

Hello,

Restrict the default LAN IP that is received by the client to only be able to connect to a few things:

https://skrzsecurity.net/zero-trust#:~:text=get%20to%20it.-,Architecture,-%3A

 

Regards,

 

  • 422 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!