5 ms·
I posted this in a comment response below. All of these things are actually configured by the company/library you are connecting to. They are configuration opt
by warhorse10_9 6y ago
I posted this in a comment response below.
All of these things are actually configured by the company/library you are connecting to. They are configuration options for the firewall that are enforced by global protect. Blame your library IT, not Palo Alto.
- shrubble 6y agoHave you yourself used the interface for configuration of these options? How easy is it for a non-expert to determine what the vpn client will or will not do, once deployed?
- bnjms 6y agoIt isn’t. You will have to speak with the IT staff to understand how they have it configured. If you have an issue with this use a third party open source client. The point is, any enterprise client is expected to have these features. Don’t install them on your personal laptop if you have a problem with what is expected behavior.
- musicale 6y ago> The point is, any enterprise client is expected to have these features "Features" seems like an excessively charitable word to describe spyware/malware-like behavior. Expected by whom? Certainly not library patrons. On the contrary, library patrons expect their privacy to be protected. http://www.ala.org/advocacy/privacy http://www.ala.org/advocacy/privacy
- asdfasgasdgasdg 6y ago> Expected by whom? By the people who pay Palo Alto Networks.
- msh 6y agoNo, people who pay for Spyware to spy on their employers / users.
- warhorse10_9 6y agoLet's lay this out. Let's say you are a government IT shop (it doesn't matter what level, state, nation whatever), or a bank, or a hospital, you are required by law to control how data is processed on your network. Therefore you must monitor compliance for devices connecting to your network. This is what GlobalProtect was designed for. It can be used in less restrictive environments, but the IT shop should make sure to audit the rules and policies of the client to not be overly burdensome on users. Palo Alto has numerous courses to train IT professionals to configure their products. It is on the IT professionals to configure the services correctly.
- brendoelfrendo 6y agoRight, Global Protect is great in regulated environments. You can turn on its always on functionality and devices can then be used while connected to VPN or not at all. If that setting is configured in an environment where users are connecting their personal devices, it's misconfigured, pure and simple.
- asdfasgasdgasdg 6y agoRight. The people who pay Palo Alto Networks, in other words.
- warhorse10_9 6y agoYes, I have. That interface is not for non-experts. It is for the IT professionals configuring the portal.