Force URL-Filter if GlobalProtect is disconnected

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Force URL-Filter if GlobalProtect is disconnected

L1 Bithead

Hi together!

 

Is there a possibility to force a client to use a (local/cloud) URL-Filter if the Global Protect Client is NOT connected to the gateway?

Enforce Global Protect connection / define 40 FQDN exceptions is not really a solution.

 

Maybe there is a PA product / license which cover this topic?

 

Best regards and thanks a lot in advance!

3 REPLIES 3

L0 Member

Since the filtering is done on the firewall itself it is not possible to enforce URL-filtering when you are not connected to GlobalProtect. You would need to route your traffic through the NGFW or Prisma Access.

Cyber Elite
Cyber Elite

Hello,

 

Adding onto what @TeemuH provided. If you dont want Global Protect to be connected you would need a web proxy of some sort. Palo does provide a Prisma Access secure web gateway./ web proxy that you could look at purchasing if it fits for you. I would reach out to your sales team to learn more.  

L1 Bithead

Hi together, 

 

Thanks a lot for your feedbacks!

In general I tried to bypass a "proxysolution" but it looks like we have to search in this direction..

 

Best regards and thanks a lot again!

  • 615 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!