How does GlobalProtect Enforcer function when Internal Host Detection (IHD) is configured and the configuration do not have Internal Gateways defined? 

How does GlobalProtect Enforcer function when Internal Host Detection (IHD) is configured and the configuration do not have Internal Gateways defined? 

557
Created On 07/02/25 15:01 PM - Last Modified 03/20/26 20:45 PM


Question




Environment




Answer


In this case GlobalProtect will treat the tunnel status as "Internal" and blocking is NOT enforced.



Additional Information


Additional details, in an alternate scenario. 

  • When Internal Host Detection (IHD) is not configured, and the network-type identified is Internal, but both External/Internal Gateways are configured, the GlobalProtect will assume the network-type as Internal and will connect to the Internal Gateway. After successfully establishing connection to the Internal Gateway, the enforcer will disengage, unblocking traffic. 
  • Tunnel or No Tunnel for Internal Gateway does not make any difference.  


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000TNTdKAO&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail