GlobalProtect
About GlobalProtect Licenses
Table of Contents
Expand All
|
Collapse All
GlobalProtect Docs
-
9.1 (EoL)
- 10.1 & Later
- 9.1 (EoL)
-
-
-
- Deploy App Settings in the Windows Registry
- Deploy App Settings from Msiexec
- Deploy Scripts Using the Windows Registry
- Deploy Scripts Using Msiexec
- SSO Wrapping for Third-Party Credential Providers on Windows Endpoints
- Enable SSO Wrapping for Third-Party Credentials with the Windows Registry
- Enable SSO Wrapping for Third-Party Credentials with the Windows Installer
-
- Mobile Device Management Overview
- Set Up the MDM Integration With GlobalProtect
- Qualified MDM Vendors
-
- Remote Access VPN (Authentication Profile)
- Remote Access VPN (Certificate Profile)
- Remote Access VPN with Two-Factor Authentication
- Always On VPN Configuration
- Remote Access VPN with Pre-Logon
- GlobalProtect Multiple Gateway Configuration
- GlobalProtect for Internal HIP Checking and User-Based Access
- Mixed Internal and External Gateway Configuration
- Captive Portal and Enforce GlobalProtect for Network Access
-
-
- End User Experience
- Management and Logging in Panorama
-
- View a Graphical Display of GlobalProtect User Activity in PAN-OS
- View All GlobalProtect Logs on a Dedicated Page in PAN-OS
- Event Descriptions for the GlobalProtect Logs in PAN-OS
- Filter GlobalProtect Logs for Gateway Latency in PAN-OS
- Restrict Access to GlobalProtect Logs in PAN-OS
- Forward GlobalProtect Logs to an External Service in PAN-OS
- Configure Custom Reports for GlobalProtect in PAN-OS
- Monitoring and High Availability
-
- About GlobalProtect Cipher Selection
- Cipher Exchange Between the GlobalProtect App and Gateway
-
- Reference: GlobalProtect App Cryptographic Functions
-
- Reference: TLS Ciphers Supported by GlobalProtect Apps on macOS Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Windows 10 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Windows 7 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Android 6.0.1 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on iOS 10.2.1 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Chromebooks
- Ciphers Used to Set Up IPsec Tunnels
- SSL APIs
-
6.3
- 6.3
- 6.2
- 6.1
- 6.0
- 5.1
-
- Download and Install the GlobalProtect App for Windows
- Use Connect Before Logon
- Use Single Sign-On for Smart Card Authentication
- Use the GlobalProtect App for Windows
- Report an Issue From the GlobalProtect App for Windows
- Disconnect the GlobalProtect App for Windows
- Uninstall the GlobalProtect App for Windows
- Fix a Microsoft Installer Conflict
-
- Download and Install the GlobalProtect App for macOS
- Use the GlobalProtect App for macOS
- Report an Issue From the GlobalProtect App for macOS
- Disconnect the GlobalProtect App for macOS
- Uninstall the GlobalProtect App for macOS
- Remove the GlobalProtect Enforcer Kernel Extension
- Enable the GlobalProtect App for macOS to Use Client Certificates for Authentication
-
6.1
- 6.1
- 6.0
- 5.1
-
6.3
- 6.3
- 6.2
- 6.1
- 6.0
- 5.1
End-of-Life (EoL)
About GlobalProtect Licenses
If you want to use GlobalProtect to provide a secure
remote access or virtual private network (VPN) solution via single
or multiple internal/external gateways, you do not need any GlobalProtect
licenses. However, to use some of the more advanced features (such as
HIP checks and associated content updates, support for the GlobalProtect
mobile app, or IPv6 support) you must purchase an annual GlobalProtect
Gateway license. This license must be installed on each firewall
running a gateway(s) that:
- Performs HIP checks
- Supports the GlobalProtect app for mobile endpoints
- Supports the GlobalProtect app for Linux endpoints
- Provides IPv6 connections
- Split tunnels traffic based on the destination domain, application process name, or HTTP/HTTPS video streaming application.
- Supports identification of managed devices using the endpoint’s serial number on gateways
- Enforces GlobalProtect connections with FQDN exclusions
For GlobalProtect Clientless VPN, you must also install a GlobalProtect
Gateway license on the firewall that hosts the Clientless VPN from the
GlobalProtect portal. You also need the GlobalProtect
Clientless VPN dynamic updates to use this feature.
Feature | Gateway License Required? |
---|---|
Single external gateway (Windows and macOS) | — |
Single or multiple internal gateways | — |
Multiple external gateways | — |
Internet of things
(IoT) devices | ![]() |
HIP Checks | ![]() |
Identification of managed devices using
the endpoint serial number on gateways | ![]() |
HIP-based policy enforcement based on the endpoint
status | ![]() |
App for endpoints running Windows and macOS | — |
Mobile app for endpoints running iOS, Android, Chrome
OS, and Windows 10 UWP | ![]() |
App for endpoints running Linux | ![]() |
App for endpoints running IoT | ![]() |
IPv6 for external gateways | ![]() |
IPv6 for internal gateways (change
to default behavior—starting with GlobalProtect app 4.1.3, a GlobalProtect
subscription is not required for this use case) | — |
Clientless VPN (Not supported
on multi-VSYS firewalls if the Clientless VPN traffic must traverse
multiple virtual systems) | ![]() |
Split tunneling based on destination domain,
client process, and video streaming application | ![]() |
Split DNS | ![]() |
![]() |
See Activate Licenses for
information on installing licenses on the firewall.