Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

User-ID and Internal Gateway

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

User-ID and Internal Gateway

L1 Bithead

Hello guys,

 

I want to implement GlobalProtect with Internal and External Gateway. Internal gateway will be used for User-ID and External Gateway for Remote Access.

Is there a way to prevent users from disconnecting GP when inside corporate network and allow them to disconnect when outside corporate network ?

 

Thanks !

 

Regards

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Hello,

I can think of several things:

  • Configure your policies with user-id's and active directory groups. That way if they disable it and try to get to internal resources, etc, they are limited to what they can get to.
  • Force everyone to VPN in, a step closer to zero trust. I wrote and article on it.

I'm sure there are other options.

 

Regards,

View solution in original post

Cyber Elite
Cyber Elite

@seag,

The connection method is setup on the portal and not the gateway, so that becomes a bit more convoluted. If using an MDM you can kind of work around that by modifying registry keys conditionally, but not something I would really recommend. Either option that @OtakarKlier mentioned would be workable solutions.

 

I would highly recommend at this point that you just enforce a VPN connection at all times on issued devices and just not allow someone to disable the agent. I've rarely come across valid use cases for being allowed to disable the VPN on an issued device when out of the office.

If this is a BYOD environment then you could easily just do the first option that @OtakarKlier brought up. There's some aspects that you'd have to think about when it comes to your DHCP lease times and User-ID timeout values, but that would effectively allow what you want.

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

I can think of several things:

  • Configure your policies with user-id's and active directory groups. That way if they disable it and try to get to internal resources, etc, they are limited to what they can get to.
  • Force everyone to VPN in, a step closer to zero trust. I wrote and article on it.

I'm sure there are other options.

 

Regards,

Cyber Elite
Cyber Elite

@seag,

The connection method is setup on the portal and not the gateway, so that becomes a bit more convoluted. If using an MDM you can kind of work around that by modifying registry keys conditionally, but not something I would really recommend. Either option that @OtakarKlier mentioned would be workable solutions.

 

I would highly recommend at this point that you just enforce a VPN connection at all times on issued devices and just not allow someone to disable the agent. I've rarely come across valid use cases for being allowed to disable the VPN on an issued device when out of the office.

If this is a BYOD environment then you could easily just do the first option that @OtakarKlier brought up. There's some aspects that you'd have to think about when it comes to your DHCP lease times and User-ID timeout values, but that would effectively allow what you want.

L1 Bithead

@OtakarKlier 

Indeed...That will "force" them to connect.

Good article by the way !

@BPry 

Yes, you configure the connection method on the portal. I was thinking about creating another "Agent Config" on the portal with a different "Config Selection ". But you cannot choose a source IP or Network as criteria.

Your recommendation to always enforce VPN connection at all times when it is not a BYOD environment makes sense.

 

Thank you guys !

Regards,

  • 2 accepted solutions
  • 157 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!