Document
How to Configure GlobalProtect

How to Configure GlobalProtect

To implement GlobalProtect, configure: GlobalProtect client downloaded and activated on the Palo Alto Networks firewallPortal Configurationgateway Co

Related articles

How to set up the Surfshark browser extension on Chrome 9 Best Vapes for Clouds: Our Top Picks for Beginners 2024 How To Set up a VPN on a Router in 2024: Install Quickly Best VPN for Windows 10 PCs [Out of 25 Tested in 2024] Top 10 Best Free Cloud Storage Services for Linux

To implement GlobalProtect, configure:

  • GlobalProtect client downloaded and activated on the Palo Alto Networks firewall
  • Portal Configuration
  • gateway Configuration
  • routing between the trust zone and GlobalProtect client ( and in some case , between the GlobalProtect client and the untrusted zone )
  • Security and NAT policies permitting traffic between the GlobalProtect clients and Trust
    • optional : NAT Policy for GlobalProtect client to go out to the internet ( if split tunneling is not enable )
  • For ios or Android device to connect , GlobalProtect app can be used .

Certificate Configuration:How to Configure GlobalProtectHow to Configure GlobalProtect

Portal Configuration

How to Configure GlobalProtect

How to Configure GlobalProtect

 

It is recommended to first test without a Certificate Profile, which allows for simpler troubleshooting, if the initial configuration does not work as intended. First successfully configure and test basic authentication, then add the Certificate Profile for certificate authentication.
 

The portal address is the address where outside GlobalProtect clients connect. In most cases, this is the outside interface’s IP address. The gateway address is usually the same outside IP address.
 

How to Configure GlobalProtect
 

GlobalProtect Connect Methods:

  • On-demand: Requires manually connecting when access to the VPN is required.
  • User – logon : VPN is establish as soon as the user log into the machine . When SSO is enable , user credential are automatically pull from the Windows logon information and used to authenticate the GlobalProtect client user .
  • Pre-logon: VPN is established before the user logs into the machine. Machine certificate is required for this type of connection.

The Agent tab contains important information regarding what users can or cannot do with the GlobalProtect Agent. Enabling Agent User Override-with-comment allows users to disable the agent after entering a comment or reason. The comment appears in the system logs of the firewall when this user logs in next.
 

How to Configure GlobalProtect
 

Selecting the “disabled” option for Agent User Override prevents users from disabling the GlobalProtect agent:
 

How to Configure GlobalProtect
 

gateway Configuration
 

For the initial testing, Palo Alto Networks recommends configuring basic authentication. When everything has been tested, adding authentication via client certificates, if necessary, can be added to the configuration.
 

How to Configure GlobalProtect

How to Configure GlobalProtect
 

To authenticate devices with a third-party VPN application, check “Enable X-Auth Support” in the gateway’s Client Configuration. Group Name and password must be configured for this setting.
 

How to Configure GlobalProtect

 

In most cases, for firewalls with static public IP addresses, set the inheritance source to none.
 

The IP pool settings information is important, because it is the pool of IP addresses that the firewall assigns to connecting GP clients. Even if Global Connect clients need to be considered as part of the local network, to facilitate routing, Palo Alto Networks does not recommend using an IP pool in the same subnet as the LAN address pool. Internal servers automatically know to send packets back to the gateway if the source is another subnet. If the GP clients were issued IP addresses from the same subnet as the LAN, then the internal LAN resources would never direct their traffic intended for the GP clients to the Palo Alto Networks Firewall (default GW).

How to Configure GlobalProtect

Access Routes:

 

Access routes are the subnets to which  GlobalProtect clients are expected to connect. In most cases this is the LAN networks. To force all traffic to go through the firewall, even traffic intended for the Internet, the network that needs to be configured is “0.0.0.0/0,” which means all traffic.

How to Configure GlobalProtect

If 0.0.0.0/0 is configured, the security rule can then control what internal LAN resources the GlobalProtect clients can access. If a security policy does not permit traffic from the GlobalProtect clients zone to the Untrust the untrusted zone, then from the GlobalProtect clients connected to the Palo Alto Networks firewall through the SSL VPN, then those clients can access only local resources and are not be allowed on the internet:
 

How to Configure GlobalProtect

How to Configure GlobalProtect 

The GlobalProtect clients zones and tunnels must be included in the same virtual router as the other interfaces.