Ovel , hi ! Appreciate your detailed instruction. I started from very simple scenario , just internal portal without Gateway detection. As I said GP shows that "you are in internal corporate network" but under Connection tab I don't see "YES" as you marked in red. I have "user-id" enable on all zones as soon as my device is in lab mode at this moment. only two reasons which I see right now : 1.certificate issues/ because I have self-signed , and some errors under GP client logs. 2. user-id matching problem. Because under monitor->global protect-> source user shows as domain\username. Might it be the problem ? Under monitor->user-id - i don't see anything .
... View more