Prisma Access Mobile Users license (for use with Prisma
Access)
GlobalProtect gateway license (for use with PAN-OS)
GlobalProtect app 6.3 and later
OS Support: Windows and
macOS
Content release version: 8833-8679 and
later
The intelligent portal selection feature enables automatic selection of the
appropriate portal when a user travels across multiple countries for seamless and
secure connectivity. After you configure intelligent portal in your environment,
you're automatically routed to the appropriate Prisma Access portal based on your
country location. For example, when you travel to China, you are directed to the
China Prisma Access portal and to the North America portal when you're in the United
States. This eliminates the need for manual selection of portals and improves the
end user experience.
The intelligent portal feature is supported for the following modes.
Always-On and Always-On (Pre-logon)
Connect Before Logon if there are no portal addresses defined
Intelligent portal is not supported for Connect Before Logon if a portal list
is defined and for On-Demand mode.
Follow the steps below to configure and use the intelligent portal feature in your
environment.
Configure intelligent portal.
Current Environment
Deployment Steps
Fresh install of GlobalProtect 6.3 and later on Windows
and macOS
Deploy GlobalProtect with a command line option to add
the intelligent portal feature:
For
example, the following command deploys GlobalProtect
with intelligent portal and defines the portals for USA
and Canada. You can define multiple portals for a
country.
Existing installation of GlobalProtect 6.3 and later for
Windows
If GlobalProtect 6.3 or higher is already installed in
your environment, you can add the following keys to the
Windows Registry (path HKEY_LOCAL_MACHINE\SOFTWARE\Palo Alto
Networks\GlobalProtect\Settings\).
You must enable intelligent portal on the portal even if you defined the
optional key REG ADD "HKLM\Software\Palo Alto
Networks\GlobalProtect\Settings" /v intelligent-portal /t REG_SZ /d
yes in the Windows Registry or macOS plist.
The following section describes how intelligent portal works
after it is configured.
When the end user logs in to the GlobalProtect app, GlobalProtect automatically
selects the portal defined in the portal country map for that location. If there
are multiple portals defined for a country, GlobalProtect selects the first
portal for that country.
If the user manually selects a different portal for that country from the portal
map, GlobalProtect directs the user to this portal for subsequent sessions. The
portal is retained when the app is refreshed or the computer goes to sleep.
If the user manually selects a portal that isn't defined in the country map,
this portal is retained for the session. When the GlobalProtect app is refreshed
or the computer wakes up from sleep, GlobalProtect automatically directs them to
the portal defined in the portal country map for that location. If there are
multiple portals defined for that portal, GlobalProtect selects the first portal
for that country.
Logs for the intelligent portal feature are included in the
GlobalProtectLogs.tgz file. See the highlighted rows in the
screenshot below.