- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
11-08-2024 08:59 AM
Hello guys,
I want to implement GlobalProtect with Internal and External Gateway. Internal gateway will be used for User-ID and External Gateway for Remote Access.
Is there a way to prevent users from disconnecting GP when inside corporate network and allow them to disconnect when outside corporate network ?
Thanks !
Regards
11-08-2024 01:42 PM
Hello,
I can think of several things:
I'm sure there are other options.
Regards,
11-11-2024 02:12 PM
The connection method is setup on the portal and not the gateway, so that becomes a bit more convoluted. If using an MDM you can kind of work around that by modifying registry keys conditionally, but not something I would really recommend. Either option that @OtakarKlier mentioned would be workable solutions.
I would highly recommend at this point that you just enforce a VPN connection at all times on issued devices and just not allow someone to disable the agent. I've rarely come across valid use cases for being allowed to disable the VPN on an issued device when out of the office.
If this is a BYOD environment then you could easily just do the first option that @OtakarKlier brought up. There's some aspects that you'd have to think about when it comes to your DHCP lease times and User-ID timeout values, but that would effectively allow what you want.
11-08-2024 01:42 PM
Hello,
I can think of several things:
I'm sure there are other options.
Regards,
11-11-2024 02:12 PM
The connection method is setup on the portal and not the gateway, so that becomes a bit more convoluted. If using an MDM you can kind of work around that by modifying registry keys conditionally, but not something I would really recommend. Either option that @OtakarKlier mentioned would be workable solutions.
I would highly recommend at this point that you just enforce a VPN connection at all times on issued devices and just not allow someone to disable the agent. I've rarely come across valid use cases for being allowed to disable the VPN on an issued device when out of the office.
If this is a BYOD environment then you could easily just do the first option that @OtakarKlier brought up. There's some aspects that you'd have to think about when it comes to your DHCP lease times and User-ID timeout values, but that would effectively allow what you want.
11-12-2024 04:46 AM
Indeed...That will "force" them to connect.
Good article by the way !
Yes, you configure the connection method on the portal. I was thinking about creating another "Agent Config" on the portal with a different "Config Selection ". But you cannot choose a source IP or Network as criteria.
Your recommendation to always enforce VPN connection at all times when it is not a BYOD environment makes sense.
Thank you guys !
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!