| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
When used in conjunction with User-ID and/or
HIP checks, an internal gateway provides a secure, accurate method
of identifying and controlling traffic by user and/or device state,
replacing other network access control (NAC) services. Internal
gateways are useful in sensitive environments that require authenticated
access to critical resources.
In a configuration with only
internal gateways, all endpoints must be configured with User-Logon
(Always On); On-Demand mode is not supported. It is also recommended
that you configure all client configurations to use single sign-on
(SSO). In addition, since internal hosts do not need to establish
a tunnel connection with the gateway, the IP address of the physical
network adapter on the endpoint is used.
In this quick config,
the internal gateways enforce group-based policies that allow users
in the Engineering group access to the internal source control and
bug databases and users in the Finance group access to the CRM applications.
All authenticated users have access to internal web resources. In
addition, HIP profiles configured on the gateway check each host
to ensure compliance with internal maintenance requirements, such
as whether the latest security patches are installed, whether disk
encryption is enabled, or whether the required software is installed.
GlobalProtect Internal Gateway Configuration
Use
the following steps to configure a GlobalProtect internal gateway.