<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall? in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/551978#M1617</link>
    <description>&lt;P&gt;We have over 200 users on a network, and IP addresses are assigned using DHCP. However, we have a customer request to allow internet access on ports 80 and 443 for specific individuals(may be 50 or more) via the Paloalto firewall. Please review and confirm the various configuration options.&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2023 06:54:43 GMT</pubDate>
    <dc:creator>shivunrp</dc:creator>
    <dc:date>2023-08-01T06:54:43Z</dc:date>
    <item>
      <title>In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/551978#M1617</link>
      <description>&lt;P&gt;We have over 200 users on a network, and IP addresses are assigned using DHCP. However, we have a customer request to allow internet access on ports 80 and 443 for specific individuals(may be 50 or more) via the Paloalto firewall. Please review and confirm the various configuration options.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 06:54:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/551978#M1617</guid>
      <dc:creator>shivunrp</dc:creator>
      <dc:date>2023-08-01T06:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552032#M1619</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;Is there a 1:1 mapping between users and devices, or can the users log into multiple devices? This would be a good usecase for User-ID (&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/user-id-overview#id2cbce7b3-daa8-45bf-ad85-df3415a67dc6" target="_blank"&gt;User-ID Overview (paloaltonetworks.com)&lt;/A&gt;) where you can define Security Policy based on user/ group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another alternative would be an 802.1x solution on the edge ports of your network allowing you to place certain devices/ users in a specific VLAN, which can then have a specific security policy applied to on the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you mention a DHCP based solution, then we can assume there must be a 1:1 mapping between the user and devices. The solution here is to logically divide a subnet. Say you have a DHCP scope for a /24 subnet, then carve out a /26 and use that for static reservations, eg:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;192.168.1.0/24&lt;/P&gt;
&lt;P&gt;Reserved: 192.168.1.0/26&lt;/P&gt;
&lt;P&gt;DHCP scope allocation: 192.168.1.64-192.168.1.250&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This will give you 62 useable host addresses, which you can use for static reservations once you have gathered all of the device MAC addresses. You can then create an address object for 192.168.1.0/26 and use it in whatever punitive policy you require.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2023 10:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552032#M1619</guid>
      <dc:creator>seb_rupik</dc:creator>
      <dc:date>2023-08-01T10:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552101#M1628</link>
      <description>&lt;P&gt;Ideas, given the limited information provided:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;If each of the 50 individuals has dedicated PCs, use DHCP reservations to give them certain IPs and then allow that IP range Internet access.&lt;/LI&gt;
&lt;LI&gt;Break it up into two networks.&amp;nbsp; This would be via SSID, or 802.1x auth, or many other options.&lt;/LI&gt;
&lt;LI&gt;Use Active Directory groups and User-ID, with different security rules depending on AD group membership.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 01 Aug 2023 16:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552101#M1628</guid>
      <dc:creator>AaronAxvig</dc:creator>
      <dc:date>2023-08-01T16:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552144#M1631</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/199655"&gt;@AaronAxvig&lt;/a&gt;, thanks for the reply. How about the AD integration method and local user authentication (using Captive Portal). ?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 02:01:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552144#M1631</guid>
      <dc:creator>shivunrp</dc:creator>
      <dc:date>2023-08-02T02:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552193#M1633</link>
      <description>&lt;P&gt;Yeah that should work.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 13:15:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552193#M1633</guid>
      <dc:creator>AaronAxvig</dc:creator>
      <dc:date>2023-08-02T13:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: In a DHCP environment, how can we grant certain users internet access via the Paloalto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552282#M1635</link>
      <description>&lt;P&gt;Thank you so much.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2023 01:33:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/in-a-dhcp-environment-how-can-we-grant-certain-users-internet/m-p/552282#M1635</guid>
      <dc:creator>shivunrp</dc:creator>
      <dc:date>2023-08-03T01:33:08Z</dc:date>
    </item>
  </channel>
</rss>

