GlobalProtect
About the GlobalProtect Components
Table of Contents
Expand All
|
Collapse All
GlobalProtect Docs
-
9.1 (EoL)
- 10.1 & Later
- 9.1 (EoL)
-
-
-
- Deploy App Settings in the Windows Registry
- Deploy App Settings from Msiexec
- Deploy Scripts Using the Windows Registry
- Deploy Scripts Using Msiexec
- SSO Wrapping for Third-Party Credential Providers on Windows Endpoints
- Enable SSO Wrapping for Third-Party Credentials with the Windows Registry
- Enable SSO Wrapping for Third-Party Credentials with the Windows Installer
-
- Mobile Device Management Overview
- Set Up the MDM Integration With GlobalProtect
- Qualified MDM Vendors
-
- Remote Access VPN (Authentication Profile)
- Remote Access VPN (Certificate Profile)
- Remote Access VPN with Two-Factor Authentication
- Always On VPN Configuration
- Remote Access VPN with Pre-Logon
- GlobalProtect Multiple Gateway Configuration
- GlobalProtect for Internal HIP Checking and User-Based Access
- Mixed Internal and External Gateway Configuration
- Captive Portal and Enforce GlobalProtect for Network Access
-
-
- End User Experience
- Management and Logging in Panorama
-
- View a Graphical Display of GlobalProtect User Activity in PAN-OS
- View All GlobalProtect Logs on a Dedicated Page in PAN-OS
- Event Descriptions for the GlobalProtect Logs in PAN-OS
- Filter GlobalProtect Logs for Gateway Latency in PAN-OS
- Restrict Access to GlobalProtect Logs in PAN-OS
- Forward GlobalProtect Logs to an External Service in PAN-OS
- Configure Custom Reports for GlobalProtect in PAN-OS
- Monitoring and High Availability
-
- About GlobalProtect Cipher Selection
- Cipher Exchange Between the GlobalProtect App and Gateway
-
- Reference: GlobalProtect App Cryptographic Functions
-
- Reference: TLS Ciphers Supported by GlobalProtect Apps on macOS Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Windows 10 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Windows 7 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Android 6.0.1 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on iOS 10.2.1 Endpoints
- Reference: TLS Ciphers Supported by GlobalProtect Apps on Chromebooks
- Ciphers Used to Set Up IPsec Tunnels
- SSL APIs
-
6.3
- 6.3
- 6.2
- 6.1
- 6.0
- 5.1
-
- Download and Install the GlobalProtect App for Windows
- Use Connect Before Logon
- Use Single Sign-On for Smart Card Authentication
- Use the GlobalProtect App for Windows
- Report an Issue From the GlobalProtect App for Windows
- Disconnect the GlobalProtect App for Windows
- Uninstall the GlobalProtect App for Windows
- Fix a Microsoft Installer Conflict
-
- Download and Install the GlobalProtect App for macOS
- Use the GlobalProtect App for macOS
- Report an Issue From the GlobalProtect App for macOS
- Disconnect the GlobalProtect App for macOS
- Uninstall the GlobalProtect App for macOS
- Remove the GlobalProtect Enforcer Kernel Extension
- Enable the GlobalProtect App for macOS to Use Client Certificates for Authentication
-
6.1
- 6.1
- 6.0
- 5.1
-
6.3
- 6.3
- 6.2
- 6.1
- 6.0
- 5.1
End-of-Life (EoL)
About the GlobalProtect Components
GlobalProtect provides a complete infrastructure for
managing your mobile workforce to enable secure access for all your
users, regardless of what endpoints they are using or where they
are located. This infrastructure includes the following components:
- GlobalProtect Portal
- GlobalProtect Gateways
- GlobalProtect App
GlobalProtect Portal
The GlobalProtect portal provides the management functions
for your GlobalProtect infrastructure. Every endpoint that participates
in the GlobalProtect network receives configuration information
from the portal, including information about available gateways
as well as any client certificates that may be required to connect
to the GlobalProtect gateway(s). In addition, the portal controls
the behavior and distribution of the GlobalProtect app software
to both macOS and Windows endpoints (on mobile endpoints, the GlobalProtect
app is distributed through the Apple App Store for iOS endpoints,
Google Play for Android endpoints and Chromebooks, and the Microsoft
Store for Windows 10 UWP endpoints). If you are using the Host
InformationProfile (HIP) feature, the portal also defines
what information to collect from the host, including any custom
information you require. You can Set
Up Access to the GlobalProtect Portal on an interface on
any Palo Alto Networks next-generation firewall.
GlobalProtect Gateways
GlobalProtect gateways provide security enforcement for traffic from GlobalProtect apps.
Additionally, if the HIP feature is enabled, the gateway generates a HIP report from
the raw host data the apps submit and can use this information in policy
enforcement. You can configure different types of gateways to provide
security enforcement and/or virtual private network (VPN) access for your remote
users, or to apply security policy for access to internal resources.
You can Configure
a GlobalProtect Gateway on an interface on any Palo Alto
Networks next-generation firewall. You can run both a gateway and
a portal on the same firewall, or you can have multiple distributed
gateways throughout your enterprise.
GlobalProtect App
The GlobalProtect app software runs on endpoints and
enables access to your network resources through the GlobalProtect
portals and gateways that you have deployed.
The GlobalProtect app for Windows and macOS endpoints is deployed
from the GlobalProtect portal. You can configure the behavior of
the app—for example, which tabs the users can see—in the client
configuration(s) that you define on the portal. See Define
the GlobalProtect Agent Configurations, Customize
the GlobalProtect App, and Deploy
the GlobalProtect App Software for details.
The GlobalProtect app for mobile endpoints (iOS, Android, and Windows UWP) is available through
the official store for the endpoint—the Apple App Store for iOS, Google Play for
Android, and the Microsoft Store for Windows UWP. You can alternatively Deploy the
GlobalProtect Mobile App Using Workspace ONE, which is a third-party
mobile endpoint management system.
See What
OS Versions are Supported with GlobalProtect? for more details.
The following diagram illustrates how the GlobalProtect portals,
gateways, and apps work together to enable secure access for all
your users, regardless of what endpoints they are using or where
they are located.
