Summary of Your Current GlobalProtect Configuration
Your existing GlobalProtect configuration needs to be in a working state and
include the following settings:
Infrastructure
The following settings are in place:
- Infrastructure Settings: Portal Hostname, Client DNS, Client IP
Pool
- Prisma Access Locations: US West, US East (for example)
- User Authentication: SAML via Azure (not Cloud Identity Engine)
GlobalProtect App
In the GlobalProtect App tab, the following example shows the App and Tunnel
settings using the Default profile.
App Settings
In the App Settings default profile, the following example shows the
Authentication Override cookies are enabled with the Connect method set to
Always On.
Gateways
The following is an example with Internal Host Detection enabled with
external gateways set to the highest priority.
Split Tunnel Settings
In the Exclude Traffic section in Tunnel Settings, the domains and routes
should be configured. This configuration ensures the traffic matching these
settings will not traverse the tunnel.
The following are examples of the configured domains and routes: