GlobalProtect makes it easier for you to block compromised
devices from your network by identifying a compromised device with
its
Host ID and,
optionally, serial number instead of its source IP address. This
ability can be preferable to blocking a compromised endpoint from
a network based on its IP address, because if a device’s IP address
changes (for example, if a user moves their endpoint from a work
location to their home), security policies based on IP addresses
could allow the endpoint back on the network.