Internal Host Detection

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Internal Host Detection

L1 Bithead

How do I ensure that when global protect identifies that it is on the internal network, it does not connect?

6 REPLIES 6

L4 Transporter

From PanGPS log if you see "NetworkDiscoverThread: network type is internal." That means it connected to internal network.

L2 Linker

Hello @cylusaragao 

 

If you take a look at the GlobalProtect Panel, you will see the following if you are internal to the corporate network. 

 

internal gp.png

I want it to not connect to the internal network

What is the behavior you intend GP to do when the user is internal to the network? Connect to globalprotect on an external gateway (prisma access or on-prem gateway) or to the internal corporate network? 

I hope it identifies it is on the internal network and does not connect

In order to achieve this. You have to configure internal host detection as specified in the link below. You only need to configure the IP address and the hostname under internal host detection in order to serve the purpose of not connecting to globalprotect when internal to the network. 

https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-web-interface-help/globalprotect/network-global...

 

 

 

When the user attempts to log in, the app does a reverse DNS lookup of an internal host using the specified IP Address to the specified Hostname. The host serves as a reference point that does not have to be reachable but reverse DNS lookup should be successful only when the endpoint is inside the enterprise network. If the app finds the host, the endpoint is inside the network and the app connects to an internal gateway, if configured, or the GlobalProtect app shows the connection status as internal. If the app fails to find the internal host, the endpoint is outside the network and the app establishes a tunnel to one of the external gateways.

  • 991 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!