You can configure two portals based on port numbers in the same Prisma Access tenant, with each
portal supporting a different authentication method. Enable this feature to migrate
mobile users from one authentication method to another without creating a new Prisma
Access tenant. This feature depends on the authentication
override cookie settings, and are enabled for both portals and on gateways.
When configuring multiple GlobalProtect portals with Traffic Steering, do not
configure
Accept Default Routes over Service Connections
(
Panorama
Cloud Services
Configuration
Traffic Steering
Settings
Accept Default Route over Service Connection
); if you do, mobile users cannot connect to the secondary
portal.
Contact your Palo Alto Networks account team to
activate this functionality.
The minimum required version of the GlobalProtect
Client version is 6.1.
Select
Cloud Services
Configuration
Mobile Users—GlobalProtect
Settings
Advanced
.
Enable Multiple Portal for Multiple Authentication
Methods
.
The new
portal appears for the 8443 port for the same tenant. This portal
inherits the configuration settings from the original port, which
is port 443.
Edit the portal configurations to update the authentication
settings.
Click the portal hyperlink or select
Panorama
Templates
Network
GlobalProtect
Portals
and click the portal
hyperlink.
In the
Authentication
section,
Add
a
Client
Authentication
with a different
Authentication
Profile
.
You can edit only the
Client Authentication
and
Certificate
Profile
authentication settings.
If you use certificate-based authentication in both
portals, ensure that the gateway doesn't have certificate-based
authentication.
This feature enables the authentication override
settings to generate cookie for both portals in the GlobalProtect app
settings.
This feature enables the authentication override
settings to generate and accept cookie for both portals in the tunnel
settings.
Commit all your changes to Panorama and push the configuration
changes to Prisma Access.
Click
Commit
Commit and Push
.
Edit Selections
and, in the
Prisma
Access
tab, make sure that
Mobile Users
is
selected in the
Push Scope
, then click
OK
.
Click
Commit and Push
.
Add the portals manually or using endpoint management
software in the GlobalProtect app.
Verify if you can connect to both portals with different
authentication profiles for the gateway.