Source IP Address Enforcement for Authentication Cookies
Focus
Focus
What's New in the NetSec Platform

Source IP Address Enforcement for Authentication Cookies

Table of Contents

Source IP Address Enforcement for Authentication Cookies

Enforce authentication cookies
You can configure the GlobalProtect portal or gateway to accept cookies from endpoints only when the IP address of the endpoint matches the original source IP addresses for which the cookie was issued or when the IP address of the endpoint matches a specific network IP address range. You can define the network IP address range using a CIDR subnet mask, such as /24 or /32. For example, if an authentication cookie was originally issued to an endpoint with a public source IP address of 201.109.11.10, and the subnet mask of the network IP address range is set to /24, the authentication cookie is subsequently valid on endpoints with public source IP addresses within the 201.109.11.0/24 network IP address range. For more information, see GlobalProtect — Customize App Settings.
This is an existing feature in Panorama and is now introduced in Prisma Access managed by Strata Cloud Manager.