Hardware reference guide

154 GlobalProtect Administrator’s Guide
Always On VPN Configuration GlobalProtect Quick Configs
Always On VPN Configuration
In an “always on” GlobalProtect configuration, the agent connects to the GlobalProtect portal upon user logon
to submit user and host information and receive the client configuration. It then automatically establishes the
VPN tunnel to the gateway specified in the client configuration delivered by the portal without end user
intervention as shown in the following illustration.
To switch any of the previous remote access VPN configurations to an always-on configuration, you simply
change the connect method:
Remote Access VPN (Authentication Profile)
Remote Access VPN (Certificate Profile)
Remote Access VPN with Two-Factor Authentication
Switch to an “Always On” Configuration
Step 1 Select Network > GlobalProtect > Portals and select the portal configuration to open it.
Step 2 Select the
Client Configuration tab and then select the client configuration you want to modify.
Step 3 Select
user-logon as the Connect Method. Repeat this for each client configuration.
Step 4 Click
OK twice to save the client configuration and the portal configuration and then Commit the change.