Region based config selection criteria fails for Internal GlobalProtect users during External gateway selection
Symptom
Internal GlobalProtect users are unable to connect to an External gateway when Gateway Client Settings profile have source address/region restriction.
Environment
- Palo Alto Firewalls
- GlobalProtect Gateway with Public IP or Region based client configurations
- Internal Host Detection with Internal gateway
- External Gateways with Source Address/Region restriction
Cause
If user was connected to an Internal gateway (office), upon gateway selection, whatever the source region is, it is ignored as the user is internal:
|
(P11396-T11348)Debug(6265): 04/09/21 18:30:50:472 HipReportThread: network type is internal network. |
Resolution
- This is an expected behavior.
- Source address is determined as follows:
- Evaluating client’s local IP address sent by the client when the client is internal.
- Evaluating client's public IP address to determine the source region when client is external, followed by gateway config lookup.