<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can i do Multiple user VPN and different policy to access Via VPN by global protect ? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-do-multiple-user-vpn-and-different-policy-to-access-via/m-p/381000#M809</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/168556"&gt;@nfsfantasy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You would already have the user-id information to go through and modify your security rulebase to accomplish what you are looking to do, and you would hopefully have your VPN users segmented into their own zone to make things easier. You simply need to go through and create the security rulebase entries dictating what users (or groups) should have access to what resources, and then deny anything that they should have access to.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like whoever configured your GlobalProtect installation simply made a general allow-all rule for these users. That generally isn't what you would want to do.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jan 2021 14:45:19 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-01-20T14:45:19Z</dc:date>
    <item>
      <title>Can i do Multiple user VPN and different policy to access Via VPN by global protect ?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-do-multiple-user-vpn-and-different-policy-to-access-via/m-p/380914#M808</link>
      <description>&lt;P&gt;Dear All&lt;/P&gt;&lt;P&gt;I have Palo alto FW use function VPN .So my customer would like to do policy for VPN&lt;/P&gt;&lt;P&gt;like&amp;nbsp;&lt;/P&gt;&lt;P&gt;User A VPN to Palo Fw just access to zone internal&lt;/P&gt;&lt;P&gt;User B VPN to Palo FW can access to zone DMZ only&lt;/P&gt;&lt;P&gt;User C VPN to Palo FW can access to All zone&amp;nbsp;&lt;/P&gt;&lt;P&gt;this time the all VPN User can access to all zone in FW . my customer need to change it&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 08:55:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-do-multiple-user-vpn-and-different-policy-to-access-via/m-p/380914#M808</guid>
      <dc:creator>nfsfantasy</dc:creator>
      <dc:date>2021-01-20T08:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can i do Multiple user VPN and different policy to access Via VPN by global protect ?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-do-multiple-user-vpn-and-different-policy-to-access-via/m-p/381000#M809</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/168556"&gt;@nfsfantasy&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;You would already have the user-id information to go through and modify your security rulebase to accomplish what you are looking to do, and you would hopefully have your VPN users segmented into their own zone to make things easier. You simply need to go through and create the security rulebase entries dictating what users (or groups) should have access to what resources, and then deny anything that they should have access to.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It sounds like whoever configured your GlobalProtect installation simply made a general allow-all rule for these users. That generally isn't what you would want to do.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jan 2021 14:45:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-i-do-multiple-user-vpn-and-different-policy-to-access-via/m-p/381000#M809</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-01-20T14:45:19Z</dc:date>
    </item>
  </channel>
</rss>

