<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is panorama able to see only the devices in their country with RO access. in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/is-panorama-able-to-see-only-the-devices-in-their-country-with/m-p/472313#M795</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer has 2 Panorama devices in A/P. They have devices on boarded to panorama. The requirement is the specific country will be able to see only the devices in their country with RO access.&lt;/P&gt;
&lt;P&gt;The Authentication method will be SAML with SSO.&lt;/P&gt;
&lt;P&gt;Could you please suggest how this could be fulfilled and how many Metadata files and certificates will be required ?&lt;/P&gt;
&lt;P&gt;Do they need multiple SAML Identity provider and authentication profile configured ?&lt;/P&gt;
&lt;P&gt;Do they need to assign admin role and access-domain to each authentication profile ?&lt;/P&gt;
&lt;P&gt;Do they need to add them in sequence in the Panorama--&amp;gt; Management---&amp;gt; Authentication ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They checked following guide :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Identity Provider Configuration for SAML&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXP" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXP&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Configure SAML Authentication for Panorama Administrators&lt;/SPAN&gt; &lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/set-up-administrative-access-to-panorama/configure-administrative-accounts-and-authentication/configure-saml-authentication-for-panorama-administrators.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/set-up-administrative-access-to-panorama/configure-administrative-accounts-and-authentication/configure-saml-authentication-for-panorama-administrators.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer has to provide individual country access to their specific set of firewalls. So they have to create multiple access domain for them.&lt;/P&gt;
&lt;P&gt;If they go by the document then they have to create multiple authentication profile and add access domain to that.&lt;/P&gt;
&lt;P&gt;In panorama management setting they can only add a single authentication profile.&lt;/P&gt;
&lt;P&gt;Also if they add multiple authentication profile per country how many SAML IDP profile they have to create?&lt;/P&gt;
&lt;P&gt;How many SAML metadata file we need?&lt;/P&gt;
&lt;P&gt;How to attach multiple authentication profile to panorama management setting?&lt;/P&gt;
&lt;P&gt;Authentication sequence does not work properly here as per their past experience.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Really i m not sure if &lt;SPAN class="Y2IQFc"&gt;country-based access control to Panorama is possible&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;I think that Panorama cannot filter it but i&lt;SPAN class="Y2IQFc"&gt; don't know if we could with the SAML idp.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Y2IQFc"&gt;Many thanks in advance for your reply.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Y2IQFc"&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2022 14:14:13 GMT</pubDate>
    <dc:creator>RomainCouvreur</dc:creator>
    <dc:date>2022-03-11T14:14:13Z</dc:date>
    <item>
      <title>Is panorama able to see only the devices in their country with RO access.</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/is-panorama-able-to-see-only-the-devices-in-their-country-with/m-p/472313#M795</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer has 2 Panorama devices in A/P. They have devices on boarded to panorama. The requirement is the specific country will be able to see only the devices in their country with RO access.&lt;/P&gt;
&lt;P&gt;The Authentication method will be SAML with SSO.&lt;/P&gt;
&lt;P&gt;Could you please suggest how this could be fulfilled and how many Metadata files and certificates will be required ?&lt;/P&gt;
&lt;P&gt;Do they need multiple SAML Identity provider and authentication profile configured ?&lt;/P&gt;
&lt;P&gt;Do they need to assign admin role and access-domain to each authentication profile ?&lt;/P&gt;
&lt;P&gt;Do they need to add them in sequence in the Panorama--&amp;gt; Management---&amp;gt; Authentication ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;They checked following guide :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Identity Provider Configuration for SAML&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXP" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXP&lt;/A&gt;&lt;BR /&gt;&lt;SPAN&gt;Configure SAML Authentication for Panorama Administrators&lt;/SPAN&gt; &lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/set-up-administrative-access-to-panorama/configure-administrative-accounts-and-authentication/configure-saml-authentication-for-panorama-administrators.html" target="_blank"&gt;https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/set-up-administrative-access-to-panorama/configure-administrative-accounts-and-authentication/configure-saml-authentication-for-panorama-administrators.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Customer has to provide individual country access to their specific set of firewalls. So they have to create multiple access domain for them.&lt;/P&gt;
&lt;P&gt;If they go by the document then they have to create multiple authentication profile and add access domain to that.&lt;/P&gt;
&lt;P&gt;In panorama management setting they can only add a single authentication profile.&lt;/P&gt;
&lt;P&gt;Also if they add multiple authentication profile per country how many SAML IDP profile they have to create?&lt;/P&gt;
&lt;P&gt;How many SAML metadata file we need?&lt;/P&gt;
&lt;P&gt;How to attach multiple authentication profile to panorama management setting?&lt;/P&gt;
&lt;P&gt;Authentication sequence does not work properly here as per their past experience.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Really i m not sure if &lt;SPAN class="Y2IQFc"&gt;country-based access control to Panorama is possible&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;I think that Panorama cannot filter it but i&lt;SPAN class="Y2IQFc"&gt; don't know if we could with the SAML idp.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Y2IQFc"&gt;Many thanks in advance for your reply.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Y2IQFc"&gt;Best regards&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 14:14:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/is-panorama-able-to-see-only-the-devices-in-their-country-with/m-p/472313#M795</guid>
      <dc:creator>RomainCouvreur</dc:creator>
      <dc:date>2022-03-11T14:14:13Z</dc:date>
    </item>
  </channel>
</rss>

