In an Always On VPN configuration, the secure
GlobalProtect connection is always on. Traffic that matches specific
filters (such as port and IP address) configured on the GlobalProtect
gateway is always routed through the VPN tunnel. For even tighter
security requirements, you can enable VPN lockdown, which forces
the secure connection to always be on and connected in addition
to disabling network access when the app is not connected. This
configuration is similar to the Enforce GlobalProtect for
Network Access option that you would typically configure
in a GlobalProtect portal configuration.
Because Workspace ONE does not yet list GlobalProtect as an official connection provider for
Windows endpoints, you must select an alternate VPN provider, edit the settings
for the GlobalProtect app, and import the configuration back into the VPN
profile as described in the following workflow.
Use the following steps to configure an Always On VPN configuration for Windows 10 UWP endpoints
using Workspace ONE: