| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
In a GlobalProtect mixed internal and external
gateway configuration, you can configure separate gateways for VPN
access and for access to your sensitive internal resources. With
this configuration, the GlobalProtect app performs internal host
detection to determine if it is on the internal or external network.
If the app determines that it is on the external network, it attempts
to connect to the external gateways listed in its client configuration,
and then it establishes a connection to the gateway with the highest
priority and shortest response time.
If you configure
all external gateways as manual-only gateways but the GlobalProtect
connect method as User-Logon (Always On) or Pre-Logon
(Always On), the GlobalProtect app does not automatically
connect to any external gateways. GlobalProtect remains in the Not
Connected state until the external user establishes a gateway connection
manually. This behavior enables you to deploy GlobalProtect to derive User-ID
for internal users while supporting On-Demand VPN behavior
for external users.
Because security policies are defined
separately on each gateway, you have granular control over the resources
to which your external and internal users have access. In addition,
you also have granular control over the gateways to which users have
access by configuring the portal to deploy different client configurations
based on user/group membership or HIP profile matching.
In
this example, the portals and all three gateways (one external and
two internal) are deployed on separate firewalls. The external gateway
at gpvpn.acme.com provides remote VPN access to the corporate network,
while the internal gateways provide granular access to sensitive
datacenter resources based on group membership. In addition, HIP
checks are used to ensure that hosts accessing the datacenter are
up-to-date on security patches.
GlobalProtect
Deployment with Internal and External Gateways
Use
the following steps to configure a mix of internal and external
GlobalProtect gateways.