Application Persistence policies for GlobalProtect
GlobalProtect™ for Windows Unified Platform (GlobalProtect) connects to a GlobalProtect gateway on a Palo Alto Networks® next-generation firewall allowing mobile users to benefit from the protection of enterprise security. This platform requires the installation of the GlobalProtect Client on the organization's devices.
You can activate an Application Persistence policy to collect information about the functional status of the GlobalProtect Clients installed on your Windows devices and view the results in reports. You can also configure the policy to attempt to repair or reinstall the client.
Application Persistence policies for GlobalProtect are supported on devices running a supported version of the Windows operating system and one of the following versions of the GlobalProtect Client:
If you select Report higher versions as Compliant, higher versions report Compliant without running health checks.
You can configure an Application Persistence policy for GlobalProtect to enable the RAR component to attempt to repair the GlobalProtect Client if it's not functioning, or reinstall it if it's missing or can't be repaired.
NOTE Depending on the Absolute product licenses associated with your account, the Report and repair option and the Report, repair, and reinstall option may not be available.
The RAR component of the Absolute agent can respond to the following issues:
|The PanGPS service (PanGPS.exe) isn't running||The RAR component restarts the service.|
|The GlobalProtect Client failed to be repaired or the expected version isn't installed||
If the Report, repair, and reinstall option is selected in the Application Persistence policy, the RAR component downloads and installs the configured version of the client.
NOTE Downgrades are not supported. If the version installed on a device is higher than the expected version, no action is taken.
Before you activate an Application Persistence policy you need to configure the policy. You need to configure the application version in addition to the settings in Configuring Application Persistence policies.
To configure the application version:
Enter the version in GlobalProtect™ version.
- The target version must be a sequence of digits separated by a period.
- You can use wildcard "*" characters after the major version number, for example, 5.* or 5.1.*.