- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-13-2025 06:47 PM
Hi @AllDay ,
GlobalProtect does not have the capability to directly make local system changes beyond its own application configuration and VPN-related (portal/GW) settings. This means the GP client doesn't modify file systems, unrelated settings, or system-wide configurations outside the scope of the VPN client.
One thing to note is that when you're connected to their GP gateway, they could have policies in place that allow their network to communicate with their GlobalProtect client pool (your client connected to their GP).
As always, ensure you have systems in place to prevent host-based attacks and explicitly configure security policies to prevent any unintended traffic flow. It’s also a good idea to communicate with the customer to understand why the VPN connection is needed. If concerns still persist, consider connecting to their environment in a controlled VLAN and monitor client traffic while connected.
Hope this helps!