Summary of Your Current GlobalProtect Configuration
Your existing GlobalProtect configuration needs to be in a working state and
include the following settings.
Onboarding
The following settings are in place:
- Infrastructure Settings: Portal Hostname, Client DNS, Client IP Pool
- Prisma Access Locations: US West, US East (for example)
GlobalProtect Portal
Under GlobalProtect Portal, the following example shows Authentication is set to
SAML (without CIE) and the DEFAULT profile is used as part of Agent
configuration.
Agent Configuration
In the default profile, the following example shows the Authentication Override
cookies are enabled with the Connect method set to Always ON.
Gateways
The following is an example with Internal Host Detection enabled with external
gateways set to the highest priority.
GlobalProtect Gateway
Under GlobalProtect Gateway, Authentication is set to SAML (without CIE) and the
DEFAULT profile is used as part of Agent configuration. Within this profile,
Split Tunnel settings are configured as part of Agent Client Settings. This
configuration ensures the traffic matching these settings will not traverse the
tunnel.
The following are examples of the configured routes and domains: