Again, I saw this doc and followed all the steps. If it was clear from the guide how it works I wouldn't create this topic.
The goal is to restrict user's Internet access while not connected to VPN. I was hoping to configure connected/disconnected policy like it is mentioned in the guide, but it is not clear exactly how.
The guide says:
So, it says that connected policy will be inforced also when VPN is disconnected but modified according to property
Later guide says regarding this property (disconnected_in_house_fw_policy_mode):
Possible values are:
encrypt_to_allow - Connected policy will be enforced, based on last connected user. Encrypt rules will be transformed to Allow rules (default).
any_any_allow - "Any - Any - Allow" will be enforced.
So, it is not clear what does it mean "based on last connected user" and "Encrypt rules will be transformed to Allow rules", what user we talking about, what encrypt rules we talking about?
All in all not clear what this feature do exactly