Summary
In this chapter, you learned how to set up site-to-site VPN tunnels and a client-to-site VPN with GlobalProtect. You can now not only provide connectivity but also scan the client machine for compliance and know how to control the user experience. You’ve also learned how to create custom applications and custom threats that will allow you to identify packets unique to your environment and take affirmative action, and you’ve learned how to set up zone and DoS protection to defend against all kinds of packet-based attacks.
If you’re preparing for the PCNSE, remember that QoS rules are applied on the egress interface. You also need to remember how the classes apply to different profiles on different interfaces, as well as the implications of using an app override and what the benefits are of a custom application or custom threat.
In the next chapter, we will be getting hands-on with some basic troubleshooting. We will learn about session details and...