<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect - Block internet access if user does not authenticate in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392961#M1045</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138583"&gt;@Pasquale01&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Sounds like you're just looking for the "&lt;STRONG&gt;Enforce GlobalProtect Connection for Network Access"&amp;nbsp;&lt;/STRONG&gt;feature in your agent.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Mar 2021 13:19:10 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-03-23T13:19:10Z</dc:date>
    <item>
      <title>GlobalProtect - Block internet access if user does not authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392806#M1039</link>
      <description>&lt;P&gt;Is it possible to block internet access if user does not authenticate through the GP client? We don't want any access to the web on the laptop unless they fully&amp;nbsp;authenticate through Okta/GP (SAML). Would Pre-logon solve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 20:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392806#M1039</guid>
      <dc:creator>Pasquale01</dc:creator>
      <dc:date>2021-03-22T20:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Block internet access if user does not authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392944#M1042</link>
      <description>&lt;P&gt;Hi PPerrotta,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can setup a policy denying unknown users in the security policy with the action of block:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Sarc845_0-1616503110946.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30495i3A6C3592EF45332C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Sarc845_0-1616503110946.png" alt="Sarc845_0-1616503110946.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using Global Protect your user identification should work just fine so no need to worry about users not being identified when connecting to the vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Make sure your source zone and source addresses are from the VPN otherwise you might block traffic like printers etc unless you use the api to identify those devices.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;++ Edit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You might have to allow your users to go to your okta tenant &amp;lt;domain&amp;gt;.okta.com above the deny policy to allow them to authenticate if you are using internal gateways as well&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 12:42:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392944#M1042</guid>
      <dc:creator>Sarc845</dc:creator>
      <dc:date>2021-03-23T12:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Block internet access if user does not authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392958#M1044</link>
      <description>&lt;P&gt;Thanks for the feedback.. but that is all post-authentication. We are in a locked-down environment so we cant use SSO or Always on, maybe pre-logon is an option. What we want is if a user doesn't authenticate on the VPN they shouldn't be able to browse the web. Users now just skip the authentication and use it for personal browsing then connect when they need access to the corporate network. So ultimately we want to stop that behavior.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 13:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392958#M1044</guid>
      <dc:creator>Pasquale01</dc:creator>
      <dc:date>2021-03-23T13:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Block internet access if user does not authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392961#M1045</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138583"&gt;@Pasquale01&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Sounds like you're just looking for the "&lt;STRONG&gt;Enforce GlobalProtect Connection for Network Access"&amp;nbsp;&lt;/STRONG&gt;feature in your agent.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 13:19:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392961#M1045</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-03-23T13:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - Block internet access if user does not authenticate</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392965#M1046</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/138583"&gt;@Pasquale01&lt;/a&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BPry is correct, you can configure this in the Portal settings under the Agent Configurations.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 13:21:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-block-internet-access-if-user-does-not/m-p/392965#M1046</guid>
      <dc:creator>Sarc845</dc:creator>
      <dc:date>2021-03-23T13:21:33Z</dc:date>
    </item>
  </channel>
</rss>

