Netskope Community
04-03-2023 11:19 AM
Use NPA with logical condition Good afternoon everyone.
Can anyone tell me if there is any way to put a logical condition, example:
Is there a way to configure netskope to be a “second choice” connection type.
Example:
The user is in the company, on the internal network, I want the traffic not to go out through the NPA, but through our internal network.
Or, user is on VPN, I want traffic to go out through VPN instead of NPA.
Is it possible for him to identify this? Or will the priority always be the NPA?
04-04-2023 08:19 AM
Hi,
This is accomplished thanks to dynamic steering (https://docs.netskope.com/en/enabling-dynamic-steering.html#UUID-0b5b24f7-89f5-c959-2689-59309c90e77...)
You can, for instance define a DNS entry only resolvable from corp/vpn connectivity, and if this is resolved, then you can define which apps to steer or not steer in ZTNA.
Robin
04-04-2023 09:05 AM
Just be careful with on/off-prem configurations. On-prem steering exemptions happen at the proxy level, not client-side at this time. This has the potential for impact if you are running cloud services that use IP address as a means for access control.
For example, we have numerous applications that require coming from an office IP to work. If on-prem is enabled then those applications are still sent to the Netskope proxy (albeit exempted) but will come from a Netskope IP.
05-12-2023 03:03 AM
Hi Bruna,
the most immediate solution is to have the NPA gateway (*.npa.goskope.com) blocked by the corporate firewall.
Nicola
In order to view this content, you will need to sign in to your account. Simply click the "Sign In" button below
Sign In