Let's talk about GlobalProtect and whether or not it's possible to have multiple portals and gateways.
Short answer: Yes, it is possible. Thank you! Like and subscribe.
Joking aside, let's dig a little deeper into this topic.
First, let me go over the different components. What's the difference between the portal and gateway exactly?
The GlobalProtect portal provides the management functions for your GlobalProtect infrastructure. Every endpoint that participates in the GlobalProtect network receives configuration information from the portal, including information about available gateways as well as any client certificates that may be required to connect to the GlobalProtect gateway(s). In addition, the portal controls the behavior and distribution of the GlobalProtect app software to both macOS and Windows endpoints. (On mobile endpoints, the GlobalProtect app is distributed through the Apple App Store for iOS endpoints, Google Play for Android endpoints and Chromebooks, and the Microsoft Store for Windows 10 UWP endpoints.) If you are using theHost Information Profile (HIP) feature, the portal also defines what information to collect from the host, including any custom information you require. You canSet Up Access to the GlobalProtect Portalon an interface on any Palo Alto Networks next-generation firewall.
GlobalProtect gateways provide security enforcement for traffic from GlobalProtect apps. Additionally, if the HIP feature is enabled, the gateway generates a HIP report from the raw host data the apps submit and can use this information in policy enforcement. You can configure differentTypes of Gatewaysto provide security enforcement and/or virtual private network (VPN) access for your remote users, or to apply security policy for access to internal resources. You canConfigure a GlobalProtect Gatewayon an interface on any Palo Alto Networks next-generation firewall. You can run both a gateway and a portal on the same firewall, or you can have multiple distributed gateways throughout your enterprise. OK, so now that you know about the different components, let's talk about what's required to have multiple portals/gateways. Those of you who've been working with our products a while might recall that additional licensing used to be required when you wanted to configure multiple portals. That's no longer the case. By default, you can deploy GlobalProtect portals and gateways without a license.
Note: Some advanced features still require a GlobalProtect license ( annual subscription).
This license must be installed on each firewall running a gateway(s) that:
performs HIP checks
supports the GlobalProtect app for mobile endpoints
supports the GlobalProtect app for Linux endpoints
provides IPv6 connections
There are a few more features that require the GlobalProtect license. You'll find the complete matrix on the About GlobalProtect Licenses page.
Having multiple portals enables end users to manage their deployments more efficiently, as they can switch between different portals without having to re-enter the portal address each time they want to connect. When a user launches the app, the most recently connected portal is pre-selected from the portal drop-down on the GlobalProtect status panel (default). To connect to a different portal, the user can select another portal from the portal drop-down. To add, delete, or modify a portal, the user can select Manage Portals from the portal drop-down as illustrated below.
When a user connects to the portal and is authenticated by the portal, the portal sends the agent configuration to the app, based on the settings you define. If you have different roles for users or groups that need specific configurations, you can create a separate agent configuration for each user type or user group. The portal uses the OS of the endpoint and the username or group name to determine which agent configuration to deploy. As with other security rule evaluations, the portal starts to search for a match at the top of the list. When it finds a match, the portal sends the configuration to the app.
The configuration can include the following:
A list of gateways to which the endpoint can connect.
Among the external gateways, any gateway that the user can manually select for the session as illustrated below:
If a GlobalProtect portal agent configuration contains more than one gateway, the app attempts to communicate with all gateways listed in its agent configuration. The app uses the priority and response time to determine the gateway to which to connect. See how Gateway Priority in a Multiple Gateway Configuration is decided.
Having multiple gateways can be a strategic decision. Enabling secure access for your mobile workforce no matter where they are located, you can deploy additional Palo Alto Networks next-generation firewalls and configure them as GlobalProtect gateways: