GlobalProtect Configuration Requirements for Migration (Panorama)
Focus
Focus
Prisma Agent

GlobalProtect Configuration Requirements for Migration (Panorama)

Table of Contents

GlobalProtect Configuration Requirements for Migration (Panorama)

Review the GlobalProtect configuration and Panorama-specific requirements that must be in place before you enable the Prisma Agent on the same tenant.
Before migrating from GlobalProtect to Prisma Agent, ensure you meet the following requirements:
  • Prisma Access version: 6.1.0 or later
  • Dataplane version: 10.2.10-h39 / 11.2.7-h17 or later
  • Panorama Plugin version: 5.2.0-h20 or later
  • Authentication: Cloud Identity Engine for User authentication
  • Management platform: Panorama
  • Feature flag: PANORAMA.MFE feature flag enabled on the tenant
For complete prerequisite information, see Prisma Agent Prerequisites and Panorama Support for Prisma Agent.

Prepare to Migrate

Before you migrate, ensure that GlobalProtect is enabled and active on a Prisma Access Tenant managed by Panorama.

Summary of Your Current GlobalProtect Configuration

Your existing GlobalProtect configuration needs to be in a working state and include the following settings.

Onboarding

The following settings are in place:
  • Infrastructure Settings: Portal Hostname, Client DNS, Client IP Pool
  • Prisma Access Locations: US West, US East (for example)

GlobalProtect Portal

Under GlobalProtect Portal, the following example shows Authentication is set to SAML (without CIE) and the DEFAULT profile is used as part of Agent configuration.

Agent Configuration

In the default profile, the following example shows the Authentication Override cookies are enabled with the Connect method set to Always ON.

Gateways

The following is an example with Internal Host Detection enabled with external gateways set to the highest priority.

GlobalProtect Gateway

Under GlobalProtect Gateway, Authentication is set to SAML (without CIE) and the DEFAULT profile is used as part of Agent configuration. Within this profile, Split Tunnel settings are configured as part of Agent Client Settings. This configuration ensures the traffic matching these settings will not traverse the tunnel.
The following are examples of the configured routes and domains: