<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Assigning a static IP to a Global Protect user in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/447556#M2144</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36728"&gt;@Steve27596&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'd personally be looking at fixing the user-id policy issue. If the logs are showing the user properly than outside of a bug something else in your policy is causing it to not match properly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for a static assignment there is actually two ways to do this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/static-ip-address-assignment.html" target="_self"&gt;Registry reserved-ipv4 reserved-ipv6 options&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UkxCAE&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_self"&gt;Framed-IP-Address Attribute&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I would recommend going the Framed-IP-Address method if you are looking for static IP assignments. It's easier to maintain and you don't need to be monkeying around with the registry on every machine the user possibly uses, you just assign the machine object or the user a dial-in static address and be done with it.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 15 Nov 2021 04:34:53 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-11-15T04:34:53Z</dc:date>
    <item>
      <title>Assigning a static IP to a Global Protect user</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/447224#M2134</link>
      <description>&lt;P&gt;Is there a way to assign a static IP to a global protect user?&amp;nbsp; I have a couple security policies that specify userids in the source, but the policies are not getting picked up.&amp;nbsp; They are dropping to the default deny.&amp;nbsp; I verified that the userid shown on the traffic monitor matches the rule, but it is not working.&amp;nbsp; I was thinking that if I 'assigned' an IP to them when they connected via Global Protect I can write the rule using their source IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Steve&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Nov 2021 15:40:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/447224#M2134</guid>
      <dc:creator>Steve27596</dc:creator>
      <dc:date>2021-11-12T15:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning a static IP to a Global Protect user</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/447556#M2144</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36728"&gt;@Steve27596&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;I'd personally be looking at fixing the user-id policy issue. If the logs are showing the user properly than outside of a bug something else in your policy is causing it to not match properly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for a static assignment there is actually two ways to do this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/globalprotect/4-1/globalprotect-app-new-features/new-features-released-in-gp-agent-4_1/static-ip-address-assignment.html" target="_self"&gt;Registry reserved-ipv4 reserved-ipv6 options&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UkxCAE&amp;amp;lang=en_US%E2%80%A9&amp;amp;refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail" target="_self"&gt;Framed-IP-Address Attribute&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Personally, I would recommend going the Framed-IP-Address method if you are looking for static IP assignments. It's easier to maintain and you don't need to be monkeying around with the registry on every machine the user possibly uses, you just assign the machine object or the user a dial-in static address and be done with it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Nov 2021 04:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/447556#M2144</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-15T04:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning a static IP to a Global Protect user</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/447841#M2149</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;It's impossible to protect an environment unless you know where users will and will not require access to.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;I'm a strong believer in the concept of least authority. This means that I'll only provide access to the areas that are absolutely necessary.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;If they do not need it now , but they might need it in the future then give it in the future.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Allowing access to more users than completely necessary will expose you up to security risks which are best left secure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;In addition, using a specific zone only for VPN users is beneficial as well.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;While you can utilize an existing zone and subnet creating VPN users in their own subnet and zone is a way to make the security and security of users easier to manage and allows you to be more precise in your security.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;My experience has observed that it's easier to use a subnet that is specifically designed for your users when setting up VPN access.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Try to set up a subnet set up in an existing zone will be problematic at the very least.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 05:29:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/447841#M2149</guid>
      <dc:creator>camchatwebcam</dc:creator>
      <dc:date>2021-11-16T05:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Assigning a static IP to a Global Protect user</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/515891#M3192</link>
      <description>&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;A id="link_7" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36728" target="_self" aria-label="View Profile of Steve27596"&gt;&lt;SPAN class=""&gt;Dear, Steve27596,&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L1-Bithead lia-component-message-view-widget-author-username"&gt;&lt;SPAN class=""&gt;Please use LDAP authentication with global protect and assing static IP in your LDAP user dial option.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Sep 2022 04:24:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/assigning-a-static-ip-to-a-global-protect-user/m-p/515891#M3192</guid>
      <dc:creator>nazmul1553</dc:creator>
      <dc:date>2022-09-25T04:24:59Z</dc:date>
    </item>
  </channel>
</rss>

