GlobalProtect Configuration Requirements for Migration (Strata Cloud Manager)
Focus
Focus
Prisma Agent

GlobalProtect Configuration Requirements for Migration (Strata Cloud Manager)

Table of Contents

GlobalProtect Configuration Requirements for Migration (Strata Cloud Manager)

Review the GlobalProtect configuration that must be in place before you enable the Prisma Agent on the same tenant.
Before migrating from GlobalProtect to Prisma Agent, ensure you meet the following requirements:
  • Prisma Access version: 6.1.0 or later
  • Dataplane version: 10.2.10-h39 / 11.2.7-h17 or later
  • Authentication: Cloud Identity Engine for User authentication
  • Management platform: Strata Cloud Manager
  • Feature flag: ZTNA_AGENT feature flag enabled on tenant
For complete prerequisite information, see Prisma Agent Prerequisites.

Prepare to Migrate

Before you migrate, ensure that GlobalProtect is enabled and active on a Prisma Access Tenant managed by Strata Cloud Manager.

Summary of Your Current GlobalProtect Configuration

Your existing GlobalProtect configuration needs to be in a working state and include the following settings:
Infrastructure
The following settings are in place:
  • Infrastructure Settings: Portal Hostname, Client DNS, Client IP Pool
  • Prisma Access Locations: US West, US East (for example)
  • User Authentication: SAML via Azure (not Cloud Identity Engine)
GlobalProtect App
In the GlobalProtect App tab, the following example shows the App and Tunnel settings using the Default profile.
App Settings
In the App Settings default profile, the following example shows the Authentication Override cookies are enabled with the Connect method set to Always On.
Gateways
The following is an example with Internal Host Detection enabled with external gateways set to the highest priority.
Split Tunnel Settings
In the Exclude Traffic section in Tunnel Settings, the domains and routes should be configured. This configuration ensures the traffic matching these settings will not traverse the tunnel.
The following are examples of the configured domains and routes: