We have multiple gateways in our environment. Our default agent profile has always on configured. Users are balanced across the gateways.
We have a troubleshooting profile that gives users the option to disconnect and choose to try and switch to a different gateway. My question is that I would like to configure a profile that is always on but gives the user the option to switch gateways but does not give the option to disable/disconnect from VPN. Is this possible? If so how?
The reason for this is if users get on to a gateway that doesn't work well for them for what ever reason, they are hitting refresh multiple times until they eventually get to a gateway that works better for them geographically. Network->Global Protect->Portals->Agent->App-> Configuration: 'Allow user to disconnect GlobalProtect App (Always-on mode)' This is currently set to Disallow. The Troubleshooting profile has this set to 'allow with comments' The ability to choose the gateway seems to be a side effect of allowing it to be disabled. I don't want to allow disconnect, however, I do want to allow the option shown below to choose a gateway, but I do not see that as an option in the list of configuration items in this area of the config. Images while connected to the troubleshooting profile:
This is what the normal user agent profile looks like. The Gateway selection is not shown, nor is the disable option:
... View more