<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict access to internal resources by GP region in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/restrict-access-to-internal-resources-by-gp-region/m-p/548785#M534</link>
    <description>&lt;P&gt;once a user is connected they're considered as 'internal' so that limits your means of segregating them&lt;/P&gt;
&lt;P&gt;for a different region you could use IP based access (as you can assign a different pool per region), but inside the same region you're limited to the same pool for everyone. eacht gateway will get a /24 (or multiple depending on the number of connected users) but I would't recommend using that as a reliable identification method&lt;/P&gt;
&lt;P&gt;I'd suggest you create an AD group and limit which users are able to access the resource&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jul 2023 15:11:56 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2023-07-10T15:11:56Z</dc:date>
    <item>
      <title>Restrict access to internal resources by GP region</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/restrict-access-to-internal-resources-by-gp-region/m-p/548245#M531</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We would like to restrict access to internal resources (service connection) for Prisma mobile users connected to other Global Protect gateways than our main one in the UK. Does anyone know how we could go about this? We will of course have policies to allow internet access but nothing more.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Prisma IP pools include UK in emea/Europe so we can't restrict it easily by what subnet the user is in.&lt;/P&gt;
&lt;P&gt;We see how to limit source traffic in policies to individual regions but in Prisma it seems once the user connects to the GP gateway of choice (testing manual atm), they are then in the emea mobile user IP pool, therefore negating the region restriction in traffic policies as it is counted as inter-fw traffic.&lt;/P&gt;
&lt;P&gt;Can anyone point me in the right direction please?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 13:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/restrict-access-to-internal-resources-by-gp-region/m-p/548245#M531</guid>
      <dc:creator>RaoulG</dc:creator>
      <dc:date>2023-07-05T13:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict access to internal resources by GP region</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/restrict-access-to-internal-resources-by-gp-region/m-p/548785#M534</link>
      <description>&lt;P&gt;once a user is connected they're considered as 'internal' so that limits your means of segregating them&lt;/P&gt;
&lt;P&gt;for a different region you could use IP based access (as you can assign a different pool per region), but inside the same region you're limited to the same pool for everyone. eacht gateway will get a /24 (or multiple depending on the number of connected users) but I would't recommend using that as a reliable identification method&lt;/P&gt;
&lt;P&gt;I'd suggest you create an AD group and limit which users are able to access the resource&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 15:11:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/restrict-access-to-internal-resources-by-gp-region/m-p/548785#M534</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-07-10T15:11:56Z</dc:date>
    </item>
  </channel>
</rss>

