Hello Sir, Q-1 I would suggest you to enable User-ID functionality on this PA in order to achieve the same. 2 steps are mentioned below. Step-1. Users should authentication from an LDAP server. Step-2 Configure the AD with multiple groups. Each group should contain required users. Once user will authenticate through GP, the security policy will be chosen accordingly ( as per the group mapping). Such as users belongs to Engineering Dept should access Resources-1 and Resources-2 and users belongs to HR should access Resources-3 and Resources-4. For more information about User-Identification, please follow below mentioned documents. User Identification Tech Note - PAN-OS 4.0 Q-2 As per my understanding, it is not possible for the GlobalProtect client to store multiple Portal addresses in like a drop down. Thanks
... View more