Hi,
I was wondering whether someone can provide me clarification on this feature.
Palo states
"You can now disable direct access to local networks so that users cannot send traffic to proxies or local resources while connected to a GlobalProtect VPN. For example, if a user establishes a GlobalProtect VPN tunnel while connected to a public hotspot or hotel Wi-Fi, and this feature is enabled, all traffic is routed through the tunnel and is subject to policy enforcement by the firewall."
I was under the impression that security policies would enforce what a GP VPN client can access or not including local networks as well as advising the access routes. Are Palo saying local networks/zones/interfaces directly conneced to the firewall? If the security policy allows access to proxies or local resources, surely this feature would be useless.
... View more