Why does GlobalProtect IP not change to the pre-logon's IP pool when user logs off?
2935
Created On 10/24/23 20:33 PM - Last Modified 05/23/24 02:37 AM
Question
Why does GlobalProtect IP not change to the pre-logon's IP pool when user logs off?
Environment
- GlobalProtect (GP) App
- Supported GP App version
- Pre-logon connect method
- Preserve-tunnel-upon-user-logoff-timeout is set to 0
Answer
- This is an expected behavior where the user tunnel is renamed to pre-logon when the user logs off.
- "preserve-tunnel-upon-user-logoff-timeout" setting is not for pre-logon connect method.
Additional Information
- "preserve-tunnel-upon-user-logoff-timeout" set to 0 terminates the tunnel only for user-logon and on-demand connect methods.
- Security policy enforcement can be applied to "pre-logon" users by adding this username under Source User tab of the policy.
- If GUI is not available to see the users, following CLI command can be executed to see connected users.
admin@HQ> show global-protect-gateway current-user
GlobalProtect Gateway: GP-Backup-GW (0 users)
Tunnel Name : GP-Backup-GW-N
GlobalProtect Gateway: GW_Main_HQ (1 users)
Tunnel Name : GW_Main_HQ-N
Domain-User Name : :pre-logon
Computer : PC-WIN10
Primary Username : pre-logon
Region for Config : 192.168.0.0-192.168.255.255
Source Region : 192.168.0.0-192.168.255.255
Client : Microsoft Windows 10 Enterprise , 64-bit
VPN Type : Device Level VPN
Mobile ID :
Client OS : Windows
Private IP : 10.20.20.2