Courseiva
Question 22 of 504
Secure Access and VPNmediumMultiple ChoiceObjective-mapped

GlobalProtect Internal Host Detection: Prevent Traffic Hairpinning

A company is deploying GlobalProtect with internal gateways. They want to ensure that users who are inside the corporate network connect directly to internal resources without going through the firewall. Which configuration is required?

Quick Answer

The correct answer combines two settings because Internal Host Detection alone only tells the portal that a client is physically inside the corporate network; it doesn't by itself change how that client connects. IHD works by having the client try to resolve a specific internal-only DNS record or reach an internal resource that is only reachable from inside the network; success tells the portal the user is internal. What actually prevents an unnecessary tunnel from being built is the separate step of assigning that internal network 'None' as its gateway, which tells the portal not to hand the client any gateway to connect to at all. Without that second setting, an internal user could still be detected as internal yet still be assigned a gateway and pushed through a VPN tunnel back into the same network they're already sitting inside of, which is the wasteful hairpin behavior the organization wants to avoid. Together, detection plus a 'None' gateway assignment is what allows GlobalProtect to recognize internal users and then simply get out of their way. Whenever a scenario is about avoiding unnecessary tunneling for users who are already inside the network, look for both a detection mechanism and an explicit no-gateway or bypass assignment, since detection by itself doesn't change routing behavior.

⚠ Common exam trap

Test-takers frequently confuse Internal Host Detection as a gateway-side feature (Option C) or think the portal can simply assign gateways based on user location without the explicit IHD check (Option A).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set the portal's 'Internal Host Detection' to detect the internal network and set 'Gateway' to 'None' for the internal network.

GlobalProtect's Internal Host Detection (IHD) feature allows the portal to detect whether a user is inside the corporate network. When the portal detects the user is internal, it can be configured to assign 'None' as the gateway, meaning the client will not establish a VPN tunnel and will connect directly to internal resources. This ensures traffic does not hairpin through the firewall.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure the portal to assign the gateway only when the user is external.

    Why it's wrong here

    The portal can assign gateways based on network location, but the specific configuration is to set gateway to 'None' for internal.

  • Set the gateway's 'Tunnel Mode' to 'No' for internal users.

    Why it's wrong here

    Tunnel mode is not used to bypass the firewall; it controls traffic forwarding.

  • Configure the gateway agent with internal host detection.

    Why it's wrong here

    Internal host detection on the gateway is used to determine if the client is internal, but it does not prevent gateway assignment.

  • Set the portal's 'Internal Host Detection' to detect the internal network and set 'Gateway' to 'None' for the internal network.

    Why this is correct

    When the portal detects an internal host, it can be configured to not assign a gateway, allowing direct access.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PCNSE

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. A user inside the corporate network (IP: 10.1.1.5) connects to the portal. The portal detects the internal host and does not assign a gateway. However, the user still cannot access internal resources. What is the most likely issue?

medium
  • A.The gateway is not configured with a client IP pool.
  • B.The GlobalProtect client is configured to always use the gateway.
  • C.The portal's authentication profile is incorrect.
  • D.The portal is not configured with internal host detection.

Why B: When the GlobalProtect client is configured to 'always use the gateway,' it forces all traffic (including internal traffic) to be tunneled to the gateway even when the user is already inside the corporate network. The portal correctly detects the internal host and does not assign a gateway, but the client still attempts to send traffic through the gateway, which is not reachable or not configured to forward internal traffic back, breaking access to internal resources.

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This PCNSE practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSE exam.