You can configure the GlobalProtect portal or gateway to accept cookies from
endpoints only when the IP address of the endpoint matches the original source IP
addresses for which the cookie was issued or when the IP address of the endpoint
matches a specific network IP address range. You can define the network IP address
range using a CIDR subnet mask, such as /24 or /32. For example, if an
authentication cookie was originally issued to an endpoint with a public source IP
address of 201.109.11.10, and the subnet mask of the network IP address range is set
to /24, the authentication cookie is subsequently valid on endpoints with public
source IP addresses within the 201.109.11.0/24 network IP address range. For more
information, see
GlobalProtect — Customize App
Settings.
This is an existing feature in Panorama and is now introduced in Prisma Access
managed by Strata Cloud Manager.