<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect and User-ID in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406121#M1280</link>
    <description>&lt;P&gt;Yeah that makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any more information about how to set the number of authentication failures before lockout on the portal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Tue, 11 May 2021 16:03:49 GMT</pubDate>
    <dc:creator>G.Grant</dc:creator>
    <dc:date>2021-05-11T16:03:49Z</dc:date>
    <item>
      <title>Global Protect and User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406078#M1277</link>
      <description>&lt;P&gt;I want to make my GP portal more secure by adding User-ID to my GP inbound rule so that only users in the AD group can authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment source user is just set to 'any' and the VPN is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I add the group as in the attached image it breaks. I'm guessing there are some extra configuration steps i'm missing here...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that the group mapping is working fine in other rules once users are authenticated. I'm just wondering if I can utilise user-id at the first step in the authentication process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-05-11 at 14.30.05.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33758i0D77AB810A33E688/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-05-11 at 14.30.05.png" alt="Screenshot 2021-05-11 at 14.30.05.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 13:42:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406078#M1277</guid>
      <dc:creator>G.Grant</dc:creator>
      <dc:date>2021-05-11T13:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406092#M1279</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/180879"&gt;@G.Grant&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Ya by default this wouldn't work. The problem is that your firewall doesn't know who the user is when a user is attempting to connect from untrust to your GlobalProtect portal/gateway. So the SSL_VPN_IN is never going to be matched and you'll always hit the Block-In entry. For this to work, you would need to tie it with an authentication rulebase entry to feed unidentified users attempting to access GlobalProtect and have them login so that they actually have a user-id mapping on their public IP so they match your SSL_VPN_IN entry.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I honestly don't recommend you try do anything like this. Let your GlobalProtect Portal do it's job of authenticating the users. If you want to secure it as much as possible, restrict access to regions that you expect/allow users to work from and setup an automatic block for the source address after X number of GlobalProtect authentication failures.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 14:29:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406092#M1279</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-05-11T14:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406121#M1280</link>
      <description>&lt;P&gt;Yeah that makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any more information about how to set the number of authentication failures before lockout on the portal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 16:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406121#M1280</guid>
      <dc:creator>G.Grant</dc:creator>
      <dc:date>2021-05-11T16:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect and User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406392#M1284</link>
      <description>&lt;P&gt;As an alternative you can use the portal agent to only allow selected users to connect,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_1-1620829061474.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33792i40641259CED56F0E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_1-1620829061474.jpeg" alt="MickBall_1-1620829061474.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you are not in the AD group you will get this message,,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1620828718798.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/33791iB335670870FE7D92/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1620828718798.png" alt="MickBall_0-1620828718798.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 14:18:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-and-user-id/m-p/406392#M1284</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-05-12T14:18:14Z</dc:date>
    </item>
  </channel>
</rss>

