IPSec VPN | √ | √ | √ | √ |
SSL VPN | √ | √ | √ | √ |
Pre-Logon Connect Mode | — | — | — | √ |
User-Logon Connect Mode | √ Certificate or username and password | √ Certificate or username and password | √ Certificate or username and password | √ Certificate or username and password |
On-Demand Connect Mode | — | — | — | √ |
External Gateway Priority by Source Region | √ | √ | √ | √ |
Internal Gateway Selection by Source IP Address | √ | √ | √ |
|
Internal Mode | √ | √ | √ | √ |
External Mode | √ | √ | √ | √ |
IPv4 Addressing | √ | √ | √ | √ |
IPv6 Addressing | √ | √ | √ | √ |
Split Tunnel Based on Access Route | √ | √ | √ | √ |
Split Tunnel Based on Destination Domain, Client Process,
and Video Streaming Application | — | — | — | √ |
Multiple Portal Support | — | — | — | √ |
Resilient VPN | √ | √ | √ | √ |
Pre-Logon Tunnel Rename Timeout | — | — | — | √ |
Restrict Transparent App Upgrades to Internal
Network Connections | √ | — | — | √ |
Enforce GlobalProtect for Network Access | √ | — | — | √ |
Deployment of SSL Forward Proxy CA Certificates
in the Trust Store | √ | √ | √ | √ |
HIP Reports | √ | √ | √ | √ |
Run Scripts Before and After Sessions | — | √ | √ | √ |
Certificate Selection by OID | — | — | | √ |
Allow Users to Disable GlobalProtect | — | — | — | √ |
Multi-Factor Authentication (MFA) | — | — | — | √ |
SAML Authentication | — | — | — | √ |
Expired Active Directory (AD) Password Change for
Remote Users | — | — | — | √ |
Active Directory (AD) Password Change Using
the GlobalProtect Credential Provider | — | — | — | √ |
SSO (Credential Provider) | — | — | — | √ |
Kerberos SSO | — | — | — | √ |
Welcome and Help Pages | — | — | — | √ |
Headless-Mode Without Icon, Pop-Up, Dialogs, and
UI | √ | √ | √ | √ |