GlobalProtect, free download. GlobalProtect: GlobalProtect is a software that resides on the end-user’s computer. The agent can be delivered to the user automatically via Active Directory, SMS or Microsoft System Configuration Manager. In the applications list, select Palo Alto Networks - GlobalProtect. In the app's overview page, find the Manage section and select Users and groups. Select Add user, then select Users and groups in the Add Assignment dialog. In the Users and groups dialog, select B.Simon from the Users list, then click the Select button at the bottom of the. GlobalProtect™ is an application that runs on your endpoint (desktop computer, laptop, tablet, or smart phone) to protect you by using the same security policies that protect the sensitive resources in your corporate network. GlobalProtect for Windows Unified Platform connects to a GlobalProtect gateway on a Palo Alto Networks next-generation firewall allowing mobile users to benefit from the protection of enterprise security.
There are minimum cert requirements for Client Cert Auth to work with GP client 5.0 on Apple iPhone/iPad.
For simplicity, the firewall's certificate will be called as 'Server Cert' in this document.
Note: The same certificate requirements apply to all implementation for Globalprotect where Client Cert authentication is needed.
The Client certificate issued should have the Extended key usage 'clientAuth'
1. Once the certificates with all the above requirements are obtained, then install the Server certificate on the firewall.
Note: In this case, the same CA server is used to issue the Client and the Server Certificate.
If they are two different CA servers, then install both the CA server certificates on the PA firewall and mark them as 'Trusted Root CA certificate'.
2. Then install the server certificate that was issued for the Portal and Gateway by this CA.
3. Configure a SSL/TLS profile for Server Certificate.
4. Point the Portal and Gateway configuration to use this SSL/TLS Service Profile.
5. Create a Certificate Profile for the Client Certificate authentication.