Summary
In this chapter, you learned how to set up site-to-site VPN tunnels and a client-to-site VPN with GlobalProtect. You can now not only provide connectivity but also scan the client machine for compliance and know how to control the user experience.
If you’re preparing for the PCNSE, remember that the clientless VPN is a proxied connection and that applications must be created. You’ll need to understand the difference between the GlobalProtect portal and gateway and know which features require an additional license (mobile clients, split tunnels for applications and domains, HIP checks, clientless VPN, IPv6, and split DNS).
Another frequently asked question is how the gateway is selected when multiple gateways are available; see Setting up the portal earlier in this chapter for more details. In short, the answer is a combination of TLS responsiveness and gateway priority in the agent configuration. Highest priority will always be preferred unless its responsiveness...