| Where Can I Use This? | What Do I Need? |
- NGFW (managed by Panorama or Strata Cloud Manager)
- Prisma Access (managed by Panorama or Strata Cloud
Manager)
|
- GlobalProtect Gateway license or Prisma Access license with
the Mobile User subscription
|
After a GlobalProtect user connects to the
portal and is authenticated by the GlobalProtect portal, the portal
sends the agent configuration to the app, based on the settings
you define. If you have different roles for users or groups that
need specific configurations, you can create a separate agent configuration
for each user type or user group. The portal uses the OS of the
endpoint and the username or group name to determine which agent
configuration to deploy. As with other security rule evaluations,
the portal starts to search for a match at the top of the list.
When it finds a match, the portal sends the configuration to the app.
The
configuration can include the following:
A list of
gateways to which the endpoint can connect.
Among the external gateways, any gateway that the user can
manually select for the session.
The root CA certificate required to enable the app to establish
an SSL connection with the GlobalProtect gateway(s).
The root CA certificate for SSL forward proxy decryption.
The client certificate that the endpoint should present to
the gateway when it connects. This configuration is required only
if mutual authentication between the app and the portal or gateway
is required.
A secure encrypted cookie that the endpoint should present
to the portal or gateway when it connects. The cookie is included
only if you enable the portal to generate one.
The settings the endpoint uses to determine whether it is
connected to the local network or to an external network.
App behavior settings, such as what the end users can see
in their display, whether users can save their GlobalProtect password,
and whether users are prompted to upgrade their software.
If
the portal is down or unreachable, the app uses the cached version
of its agent configuration from its last successful portal connection
to obtain settings, including the gateway(s) to which the app can
connect, what root CA certificate(s) to use to establish secure
communication with the gateway(s), and what connect method to use.
Use
the following procedure to create an agent configuration.