Does changing GlobalProtect VPN to Always On require reinstalling?

Reply
Highlighted
L1 Bithead

Does changing GlobalProtect VPN to Always On require reinstalling?

I have about a hundred users remote but they don't always need to VPN. However depending on how long WFH goes, I may need them to VPN for things like WSUS windows updates.

Rather than assume everyone will follow instructions to connect to VPN (I still will), is there a way to force their connection to always connect, even if our current setup requires them to login via Okta/SAML? 
If so, would that require re-deploying the client? Or would it just update that upon their next connection to the VPN? 

Highlighted
L7 Applicator

Re: Does changing GlobalProtect VPN to Always On require reinstalling?

@JohnQuile,

Changing to Always-On doesn't require you to re-install the agent, it will simply update it's configuration in the background the next time it connects to the portal. Short answer is this will work perfectly fine, here is a KB article about getting it setup.

Highlighted
L1 Bithead

Re: Does changing GlobalProtect VPN to Always On require reinstalling?

@BPry 
Is there a way to prevent the Always On from connecting from the internal network? 

Highlighted
L7 Applicator

Re: Does changing GlobalProtect VPN to Always On require reinstalling?

Yes. Use the internal host detection within the portal config.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!