<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block user from connecting with Global Connect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/460741#M2367</link>
    <description>&lt;P&gt;First off that you for your reply. I am very new to managing firewalls and it is appreciated.&lt;/P&gt;&lt;P&gt;From reading your post I think the best way to proceed is to block the device in the&amp;nbsp;&lt;SPAN&gt;Device Quarantine list. I looked up the Host ID but when I go and click on add and put the Host ID in and click apply not errors pop up but the device never shows up in the list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So will try to figure that one out. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Thank you again,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tom&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 22:23:35 GMT</pubDate>
    <dc:creator>thoffman</dc:creator>
    <dc:date>2022-01-24T22:23:35Z</dc:date>
    <item>
      <title>Block user from connecting with Global Connect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/460671#M2360</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have tried searching and must be missing something.&lt;/P&gt;&lt;P&gt;I am trying to block a user from attaching Global Protect. From what I have read you should be able to go to&amp;nbsp;&lt;SPAN&gt;Network&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;GlobalProtect&amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;Device Block List and add the device\user to the list. The issue I am running into is that I do not see this list when I go there.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am running PANOS 10.1.3, does this list need to be created? Does someone have a link to the directions on how to create\find this list?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tom&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 18:47:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/460671#M2360</guid>
      <dc:creator>thoffman</dc:creator>
      <dc:date>2022-01-24T18:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: Block user from connecting with Global Connect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/460680#M2361</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/172185"&gt;@thoffman&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Whatever you were looking at must have been older. If you wish to block the device from connecting you would simply add it under Device -&amp;gt; Device Quarantine, and at that point the device won't be able to connect to GlobalProtect anymore.&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/device/device-device-quarantine.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-web-interface-help/device/device-device-quarantine.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're looking to block an individual user, regardless of device, there's a few ways you can do so:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* Remove the user from the Gateway Agent configuration so they don't have a configuration to hand out. This would allow them to authenticate technically, but GlobalProtect won't connect as they don't have an assigned agent config.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* Remove the user from the AD groups (assuming active directory) that actually power authentication. So as an example you might have a Authorized-VPN-Users security group that is attached to the Authentication Profile in the Allow List, simply remove that user from the associated groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* Create a specific Agent configuration for this user, above all other configs in the list, that gives them a blocked IP Pool. Anyone assigned this agent config could be allocated an IP Pool that simply has a deny entry at the begining of your security rulebase as that while they'll be allowed to "connect", they can't process any network traffic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;* Setup a deny rule and just target their User-ID entry as the source-user and deny all of the traffic from that User-ID coming across your GlobalProtect security zones.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Removing them from the authentication profile so they simply can't authenticate is the "correct" answer for this, but any of these will technically work perfectly fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 19:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/460680#M2361</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-24T19:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: Block user from connecting with Global Connect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/460741#M2367</link>
      <description>&lt;P&gt;First off that you for your reply. I am very new to managing firewalls and it is appreciated.&lt;/P&gt;&lt;P&gt;From reading your post I think the best way to proceed is to block the device in the&amp;nbsp;&lt;SPAN&gt;Device Quarantine list. I looked up the Host ID but when I go and click on add and put the Host ID in and click apply not errors pop up but the device never shows up in the list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So will try to figure that one out. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Thank you again,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tom&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 22:23:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/460741#M2367</guid>
      <dc:creator>thoffman</dc:creator>
      <dc:date>2022-01-24T22:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Block user from connecting with Global Connect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/461187#M2382</link>
      <description>&lt;P&gt;Just an update that I did add the Host ID to the Device Quarantine list and it does show the device and being Quarantined in the Global Protect logs.&lt;/P&gt;&lt;P&gt;The funny thing is that there is nothing in the Device&amp;gt;Device Quarantine list in the firewall?&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 17:23:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/461187#M2382</guid>
      <dc:creator>thoffman</dc:creator>
      <dc:date>2022-01-26T17:23:15Z</dc:date>
    </item>
    <item>
      <title>Re: Block user from connecting with Global Connect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/462100#M2403</link>
      <description>&lt;P&gt;Just a follow up that the reason the &lt;SPAN&gt;Device Quarantine&lt;/SPAN&gt; list is that there is a bug in 10.1.3 that causes this. We were told to roll back to 10.0.8-h8 and all the issues cleared up.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 31 Jan 2022 13:57:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/block-user-from-connecting-with-global-connect/m-p/462100#M2403</guid>
      <dc:creator>thoffman</dc:creator>
      <dc:date>2022-01-31T13:57:57Z</dc:date>
    </item>
  </channel>
</rss>

