• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

War Room

Shells From Above

RSM logo

  • Home
  • About
  • Blog
  • Talks/Whitepapers
  • Tools
  • Recreation
Home > Defense > COVID-19 and Palo Alto’s GlobalProtect

COVID-19 and Palo Alto’s GlobalProtect

March 13, 2020 By Tim Lambes

With the recent issues involving COVID-19, and the recent closure announcements of college campuses, organizations are beginning to review their capacity to support a larger than normal remote workforce. In the event an office closing, is your organization prepared to support the influx of users attempting to gain access to the corporate network remotely. Can your organization do this with security in mind?

The good news is Palo Alto Firewalls, whether physical or virtual, includes GlobalProtect free for both Windows and Mac installations, and if needed, can support additional operating systems with the purchase of an annual GlobalProtect license. The goal of GlobalProtect is to extend the prevention capabilities an organization enforces internally to its mobile workforce, regardless of their location. By enabling and utilizing GlobalProtect your organization can extend its security policies to all users at any location and still provide visibility into the all application traffic. This is extremely useful for any organization dealing with sensitive data, who require auditable events to still be logged and alerted to.

Additionally, GlobalProtect provides the capacity to enable, and secure, non-company owned devices while still enforcing a zero trust infrastructure. For non-company devices, users can download the client software from the GlobalProtect gateway using the URL configured for access. They will simply have to authenticate using their domain credentials in order to get the client. This can come in handy in the event an office closure becomes extended, and not all employees have company issued endpoints. By using the capabilities within GlobalProtect, the organization has additional options for enabling the remote employee. Connecting to GlobalProtect will provide visibility into a user’s application activity, user-based policy control, user-based analysis/reporting/forensics and can also neutralize credential theft if configured correctly.

With the potential influx in the remote workforce, a challenge could be having enough internet bandwidth to handle the extra traffic.  The Prisma Access license added to an existing Panorama deployment will help with this challenge. Prisma Access is a cloud-based infrastructure that utilizes the GlobalProtect gateways to secure mobile users with company laptops, phones and tablets. The functionality is the same from a user’s perspective but will be slightly different for an admin since the configuration is cloud-based.

Tim Lambes

Primary Sidebar

Categories

  • Defense
  • Forensics
  • Offense
  • Physical
  • R&D

Most Viewed Posts

  • DLL Injection Part 1: SetWindowsHookEx 11.1k views
  • Sophos UTM Home Edition – 3 – The Setup 10.9k views
  • Leveraging MS16-032 with PowerShell Empire 10.1k views
  • Bypassing Gmail’s Malicious Macro Signatures 10k views
  • How to Bypass SEP with Admin Access 9.1k views

Footer

  • Facebook
  • LinkedIn
  • Twitter
  • Tools
  • About
  • RSM US LLP

(312) 634-3400

30 S. Wacker Drive Suite 3300
Chicago, IL 60606

Copyright © 2026 RSM US LLP. All rights reserved. RSM US LLP is a limited liability partnership and the U.S. member firm of RSM International, a global network of independent audit, tax and consulting firms. The member firms of RSM International collaborate to provide services to global clients, but are separate and distinct legal entities that cannot obligate each other. Each member firm is responsible only for its own acts and omissions, and not those of any other party. Visit for more information regarding RSM US LLP and RSM International.