This article will demonstrate how to install and use Palo Alto GlobalProtect ZTNA/VPN, which is required to access certain shared drives or services required by Deakin.
| Palo Alto GlobalProtect ZTNA/VPN automatically disconnects after a continuous period of inactivity, or if your computer is turned off/sleeps. You will need to re-log in to reconnect to required services. |
Installation Instructions
| If you're installing for a Deakin-managed Windows PC, you simply need to search for GlobalProtect in Company Portal or Self Service+. |
- First, please visit the ztna.deakin.edu.au
- Login the portal page via Deakin Username and Deakin Password
- You can access the ZTNA download page after you login the page successfully.

- Select Download Windows 32/64 bit GlobalProtect agent that corresponds to the operating system running on your computer.
- Once the file has finished downloading, navigate to your Downloads folder.
Open the software installation file "GlobalProtect64.msi"

- In the GlobalProtect Setup Wizard, click "Next".
Click "Next" to accept the default installation folder (C:\Program Files\Palo Alto Networks\GlobalProtect) and then click "Next" twice.
After installation is complete, Close the wizard.
Using GlobalProtect
- Whenever your log into your computer, GlobalProtect Client will automatically be docked in your active apps. This is visible on the far-right side of your Start Bar.
If it's not open, navigate to your Start Menu, search for, and open, GlobalProtect Client.
- In the window that opens up, enter the Portal 'ztna.deakin.edu.au', then select "Connect".

- A pop-up window will appear. Enter your Deakin Username, and your Deakin Password.
Select "Approve with DUO" to verify your identity, then it pushes notification to your smartphone DUO app to get approval.



- A notification will pop up on your screen to Approve or Reject. Hit the green tick (Approve)

- If your smartphone does not have Internet connectivity and is not connected to a Wi-Fi network, you can use a Duo Mobile passcode.


Select “Enter a Passcode” and enter the generated 6-digit passcode on your phone in the Passcode field.

To generate the passcode on your phone


- If all log-in information is correct, you should log in successfully after a brief period of GlobalProtect loading.
Once user is authenticated by the portal, the GlobalProtect will be "Connected" and the "Best Available Gateway" will be assigned to user.

By default, user will be connected to "Best Available Gateway" automatically.
The GlobalProtect uses a network discovery method to select the best available gateway from the multiple available gateway options ('ZTNA-Gateway-BW' and 'ZTNA-Gateway-WF').
GlobalProtect attempts to communicate with all the gateways and uses criteria such as gateway priority, load, and response time from each gateway to determine which is the best available gateway
- User will be connected to one of the gateways ('ZTNA-Gateway-BW' or 'ZTNA-Gateway-WF') as the 'Best Available Gateway'. Both of them are unencrypted gateway.
If you need to connect to encrypted gateway, click 'Change Gateway' then select the 'ZTNA-Encrypted-Gateway'

Unencrypted access is for the user on a "Trusted" Wi-Fi network such as your home Wi-Fi.
Encrypted access is for the user on public Wi-Fi, or working overseas.
- If you need to disconnect, click the burger icon on the right top of the application, then choose the "Disconnect" button.
Next time you need to connect to the ZTNA/VPN, please be aware you will be prompted to sign in again.
