<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Separation of profiles for authorization and authentication in GlobalProtect in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/separation-of-profiles-for-authorization-and-authentication-in/m-p/511230#M3065</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/228346"&gt;@nickalecks&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Yes, that is actually how GlobalProtect really works.&lt;/P&gt;
&lt;P&gt;- For both GP portal and gateway you first authenticate the user, which is defined under Authentication Tab&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1659962307205.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43041iD4ABB8647E444F1B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1659962307205.png" alt="Astardzhiev_0-1659962307205.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here you specify what Authentication profile (authentication method) should GP apply when users are trying to connect. Here you can have different authentication methods based on client OS.&lt;/P&gt;
&lt;P&gt;- Once the user is authenticated you can use the Group Mapping (which is retrieved over LDAP) to apply different portal or gateway configuration. This is done under Agent tab (again for both portal and gateway)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1659962492342.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43042iCB81FE13A12249D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1659962492342.png" alt="Astardzhiev_1-1659962492342.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here you can specify user group that FW is retrieving from the configured Group Mapping and have different configuration profiles based on user/user group and/or client OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 Aug 2022 12:43:39 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2022-08-08T12:43:39Z</dc:date>
    <item>
      <title>Separation of profiles for authorization and authentication in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/separation-of-profiles-for-authorization-and-authentication-in/m-p/509728#M3014</link>
      <description>&lt;P&gt;Hello friends! Help me please.&lt;BR /&gt;I need advice on authentication and authorization when connecting to a GP.&lt;BR /&gt;Is it possible to separate these roles?&lt;/P&gt;
&lt;P&gt;For example: authenticate using SAML.&lt;BR /&gt;And then check this user for belonging to groups in LDAP, and depending on these groups, send him to the gateway / send him settings / apply policies.&lt;/P&gt;
&lt;P&gt;In general, authenticate via SAML, and authorize via LDAP.&lt;/P&gt;
&lt;P&gt;There were no such cases in the documentation.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 09:31:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/separation-of-profiles-for-authorization-and-authentication-in/m-p/509728#M3014</guid>
      <dc:creator>nickalecks</dc:creator>
      <dc:date>2022-07-24T09:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Separation of profiles for authorization and authentication in GlobalProtect</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/separation-of-profiles-for-authorization-and-authentication-in/m-p/511230#M3065</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/228346"&gt;@nickalecks&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Yes, that is actually how GlobalProtect really works.&lt;/P&gt;
&lt;P&gt;- For both GP portal and gateway you first authenticate the user, which is defined under Authentication Tab&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1659962307205.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43041iD4ABB8647E444F1B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1659962307205.png" alt="Astardzhiev_0-1659962307205.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here you specify what Authentication profile (authentication method) should GP apply when users are trying to connect. Here you can have different authentication methods based on client OS.&lt;/P&gt;
&lt;P&gt;- Once the user is authenticated you can use the Group Mapping (which is retrieved over LDAP) to apply different portal or gateway configuration. This is done under Agent tab (again for both portal and gateway)&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1659962492342.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43042iCB81FE13A12249D9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1659962492342.png" alt="Astardzhiev_1-1659962492342.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Here you can specify user group that FW is retrieving from the configured Group Mapping and have different configuration profiles based on user/user group and/or client OS.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 12:43:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/separation-of-profiles-for-authorization-and-authentication-in/m-p/511230#M3065</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-08-08T12:43:39Z</dc:date>
    </item>
  </channel>
</rss>

