Need Help on Configuring GlobalProtect VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Need Help on Configuring GlobalProtect VPN

L0 Member

Hello there,

 

I am working on setting up GlobalProtect VPN for our organization and could use some advice. We have a mixed environment with Windows, macOS, and Linux machines, and we're looking to ensure a seamless experience for our users.

 

Specifically; I am interested in hearing about best practices for;

Configuring GlobalProtect for a mixed OS environment.

Ensuring compatibility and performance across different devices.

Implementing security measures, such as two-factor authentication.

Managing and monitoring VPN usage and performance.

 

Also, I have gone through this; https://docs.paloaltonetworks.com/globalprotect/9-1/globalprotect-admin/globalprotect-gateways/confi...aws-globalprotect-gateway which definitely helped me out a lot.

 

If you have any experience or tips to share regarding these topics, I would greatly appreciate it.

Also; if there are any common pitfalls or challenges to watch out for, please let me know.

 

Thank you in advance for your help and assistance.

2 REPLIES 2

L5 Sessionator

Hello,

 

What authentication method are you looking at using for GlobalProtect? That would really be the only thing that may affect certain configuration between those devices. If you intend to use HIP profiles as well that information gathered between ths OSs would provide different information. 

 

For example, what we've found works best is SAML authentication, this sets one authentication profile on the Palo and the SAML side handles the MFA. Certain things to consider with SAML is, that SAML can be the only authentication method if you use SAM, i.e. you cant have an authentication sequence and fail back to other methods. I believe you also can do always-on on IOS devices due to how Apple handles SAML.

Cyber Elite
Cyber Elite

Do you have GlobalProtect subscription?

To use GlobalProtect app on Linux or on mobile devices requires active subscription.

 

https://docs.paloaltonetworks.com/globalprotect/10-1/globalprotect-admin/globalprotect-overview/abou...

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 389 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!