GlobalProtect Always On VPN Configuration
Focus
Focus
GlobalProtect

GlobalProtect Always On VPN Configuration

Table of Contents

GlobalProtect Always On VPN Configuration

Where Can I Use This?What Do I Need?
  • NGFW (managed by Panorama or Strata Cloud Manager)
  • Prisma Access (managed by Panorama or Strata Cloud Manager)
  • GlobalProtect Gateway license or Prisma Access license with the Mobile User subscription
In an “Always On” GlobalProtect configuration, the app connects to the GlobalProtect portal (upon user login) to submit user and host information and receive the client configuration. The app then automatically connects and establishes a VPN tunnel to the gateway that was specified in the client configuration delivered by the portal, as shown in the following image:
To switch one of the following remote access VPN configurations to an Always On configuration, you can change the connect method:
Use the following steps to switch a remote access VPN configuration to an Always On configuration.

GlobalProtect Always On VPN Configuration - Panorama

  1. Select NetworkGlobalProtectPortals, and then select a portal configuration.
  2. On the Agent tab, select the agent configuration that you want to modify.
  3. Select App, and then set the Connect Method to User-logon (Always On).
  4. Click OK to save the agent configuration.
  5. Repeat steps 2-4 for each agent configuration that you want to modify.
  6. Click OK to save the portal configuration, and then Commit your changes.

GlobalProtect Always On VPN Configuration - SCM

  1. On Strata Cloud Manager, select ManageConfigurationNGFW and Prisma AccessDevice SettingsGlobalProtectAgent Settings.
  2. In Agent App Settings, select the agent configuration that you want to modify.
  3. In App Configuration, and set Connect to User-logon (Always On).
  4. Click OK to save the agent configuration.
  5. Repeat steps 2-4 for each agent configuration that you want to modify.
  6. Click OK to save the portal configuration, and then Commit your changes.