Configure an Always On VPN Configuration for iOS Endpoints
Focus
Focus
GlobalProtect

Configure an Always On VPN Configuration for iOS Endpoints

Table of Contents

Configure an Always On VPN Configuration for iOS Endpoints

Learn how to configure a VPN connection where the secure GlobalProtect connection is always on.
Where Can I Use This?What Do I Need?
  • Prisma Access
  • PAN-OS
  • GlobalProtect Subscription
  • Prisma Access Mobile Users license (for use with Prisma Access)
  • GlobalProtect Gateway license (for use with PAN-OS)
  • GlobalProtect app for iOS 6.1 and later releases
  • Endpoints running supported iOS releases
In an Always On VPN configuration, the secure GlobalProtect connection is always on. Traffic that matches specific filters (such as port and IP address) configured on the GlobalProtect gateway is always routed through the tunnel.
For iOS endpoints, you can configure an Always On VPN configuration on the firewall or Prisma Access.
  • To configure an Always on VPN configuration using the web user interface (on the firewall or Panorama Managed Prisma Access):
    1. Select NetworkGlobalProtectPortals.
    2. Select a portal configuration and select the Agent tab.
    3. Select an agent configuration and select the App tab.
    4. For the Connect Method, select User-logon (Always On).
    5. Click OK.
    6. Commit and push your changes to Mobile Users.
  • To configure an Always on VPN configuration from Strata Cloud Manager for Prisma Access:
    1. Select WorkflowsPrisma Access SetupGlobalProtect.
    2. Select the GlobalProtect App tab.
    3. Select an app setting.
    4. For the Connect setting in the App Configuration section, select Every time the user logs on to the machine (Always On)).
    5. Save your settings and Push Config.