<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure a global protect so that they user choose which VPN profile/group to connect? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-configure-a-global-protect-so-that-they-user-choose-which/m-p/434596#M1792</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18576"&gt;@Dereje&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you are describing is a very standard way of doing things with Cisco AnyConnect.&amp;nbsp; Because GlobalProtect (GP) users are automatically added to User-ID (the NGFW knows their name and IP at login), the firewall rules do not have to permit or deny users based on the IP pool.&amp;nbsp; You can replace the IP pools in the firewall rules with user groups.&amp;nbsp; In that way, if a user is a member of multiple groups, they will match multiple rules and have all the access they need without having to select (or change) a profile.&amp;nbsp; The only piece you need to add (if you haven't done so already) is group mapping via LDAP or the Cloud Identity Engine (PAN-OS 10.1).&amp;nbsp; For group mapping, make sure you configure the Primary Username under User Attributes because it will standardize the format of users so that it is consistent across multiple User-ID sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can assign separate IP pools based upon groups under the GP gateway &amp;gt; Agent &amp;gt; Client Settings, but I do not know how users can select their own "profile."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Fri, 17 Sep 2021 02:06:15 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-09-17T02:06:15Z</dc:date>
    <item>
      <title>How to configure a global protect so that they user choose which VPN profile/group to connect?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-configure-a-global-protect-so-that-they-user-choose-which/m-p/434583#M1791</link>
      <description>&lt;P&gt;&lt;SPAN&gt;As part of migrating from AnyConnect VPN to Global Protect remote access VPN: -&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Use Case:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We are using Azure AD for authentication and the GlobalProtect authentication profile is configured to use Azure AD for SSO authentication;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We want remote users to use GlobalProtect remote access VPN to access enterprise data center resources;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;A GlobalProtect Portal and GlobalProtect Gateway is configured on a pair of PA5260 firewalls in HA;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Each Active Directory user group has its own VPN profile, where each VPN profile has its own assigned IP pool;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When members of the group connect to the VPN, they should be getting IP addresses only from the ranges assigned to the pool;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have users that are a member of multiple Active Directory groups (which means a user can be a member of multiple VPN profiles);&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When a user connects to different VPN profile, the user should get IP address from the designated pool;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We want to accomplish:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The firewall rules on the data center firewalls are set up to permit or deny users based on the IP pool assigned to the VPN profiles (basically based on the group in Active Directory).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In the GlobalProtect configuration, how do we make users choose which VPN profile/Group to associate while they are establishing VPN connection?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I might not explaining the problem very well here, but please let me know if you have any question.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 01:04:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-configure-a-global-protect-so-that-they-user-choose-which/m-p/434583#M1791</guid>
      <dc:creator>Dereje</dc:creator>
      <dc:date>2021-09-17T01:04:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure a global protect so that they user choose which VPN profile/group to connect?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-configure-a-global-protect-so-that-they-user-choose-which/m-p/434596#M1792</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18576"&gt;@Dereje&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you are describing is a very standard way of doing things with Cisco AnyConnect.&amp;nbsp; Because GlobalProtect (GP) users are automatically added to User-ID (the NGFW knows their name and IP at login), the firewall rules do not have to permit or deny users based on the IP pool.&amp;nbsp; You can replace the IP pools in the firewall rules with user groups.&amp;nbsp; In that way, if a user is a member of multiple groups, they will match multiple rules and have all the access they need without having to select (or change) a profile.&amp;nbsp; The only piece you need to add (if you haven't done so already) is group mapping via LDAP or the Cloud Identity Engine (PAN-OS 10.1).&amp;nbsp; For group mapping, make sure you configure the Primary Username under User Attributes because it will standardize the format of users so that it is consistent across multiple User-ID sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can assign separate IP pools based upon groups under the GP gateway &amp;gt; Agent &amp;gt; Client Settings, but I do not know how users can select their own "profile."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 02:06:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-configure-a-global-protect-so-that-they-user-choose-which/m-p/434596#M1792</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-09-17T02:06:15Z</dc:date>
    </item>
  </channel>
</rss>

