<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authenticating GP users to Prisma Access with user certificates? in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/609181#M876</link>
    <description>&lt;P&gt;Interesting - do you have positive results with blocking /32 „subnets”?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’ve added my own IP address to the working embargo policy but I was still able to access both Portal &amp;amp; Gateways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Oct 2024 06:18:50 GMT</pubDate>
    <dc:creator>VTQNetwork</dc:creator>
    <dc:date>2024-10-21T06:18:50Z</dc:date>
    <item>
      <title>Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597584#M849</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;
&lt;P&gt;We are currently using an LDAP auth profile to auth our GP clients to PA. This is working fine, but the portal logs are just swamped with brute force attacks day &amp;amp; night and PAN refuses to fix this, so we are wanting to move over to certificate authentication instead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In brief, we have an AD-integrated MS PKI that issues user and machine certs via group policy. The machine certs are currently being used successfully to authenticate machines in a 'pre-logon' profile before the user logs in, so it would seem this is possible, but for the life of me I cannot figure out what is necessary to configure this for user auth &lt;STRONG&gt;through the Strata Cloud Manager&lt;/STRONG&gt; (we do not use Panorama), and I'm completely unable to locate any PAN documentation describing this configuration process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone here help?&lt;/P&gt;
&lt;P&gt;Thanks very much!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 20:02:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597584#M849</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-09-11T20:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597725#M850</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51581"&gt;@LCMember40912&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is a section called "copilot" in SCM can you paste you query to find out the configuration guidance meanwhile we are checking internally.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="husingh_0-1726167803413.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62218i4EA7D7E316FB651D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="husingh_0-1726167803413.png" alt="husingh_0-1726167803413.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 19:03:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597725#M850</guid>
      <dc:creator>husingh</dc:creator>
      <dc:date>2024-09-12T19:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597730#M851</link>
      <description>&lt;P&gt;Hi, I do not have a 'Copilot' section in SCM. Thanks for your suggestion however.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 20:44:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597730#M851</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-09-12T20:44:11Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597819#M853</link>
      <description>&lt;P&gt;I'm going to suspend this topic. My goal in moving toward cert auth was to eliminate the flood of brute-force attacks against the portal. Turns out that won't help. The web portal can't be disabled, even if GP uses cert auth, so as long as the portal is up, people are free to brute force it to their heart's content and there's absolutely nothing you can do about it until PAN gets off their butt and address it. Really bad look for an erstwhile 'security' organization...&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2024 20:43:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597819#M853</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-09-13T20:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597820#M854</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/51581"&gt;@LCMember40912&lt;/a&gt;&amp;nbsp; apology for the incovinience.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/enable-mobile-users-to-authenticate-to-prisma-access" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma-access/administration/prisma-access-mobile-users/enable-mobile-users-to-authenticate-to-prisma-access&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please go though above document(&lt;FONT face="batang,apple gothic" size="3"&gt;Enable Mobile Users to Authenticate to Prisma Access).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;This document has the available options to authenticate mobile users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2024 21:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/597820#M854</guid>
      <dc:creator>husingh</dc:creator>
      <dc:date>2024-09-13T21:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/606146#M870</link>
      <description>&lt;P&gt;Yeah, I have the same problem with brute force.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;It’s possible to deny the traffic by country, but not by the source IP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Allow Lists you can prevent sending brute force logins to your AD, but you will continue to see the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AFAIK, it’s not possible to configure security policy on the internet-portal traffic neither block by source IP address.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 16:50:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/606146#M870</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-10-17T16:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/606581#M871</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;It’s possible to deny the traffic by country, but not by the source IP."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;No, you can put subnets as well as regions in the embargo list...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 20:45:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/606581#M871</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-10-17T20:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/609181#M876</link>
      <description>&lt;P&gt;Interesting - do you have positive results with blocking /32 „subnets”?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I’ve added my own IP address to the working embargo policy but I was still able to access both Portal &amp;amp; Gateways.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 06:18:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/609181#M876</guid>
      <dc:creator>VTQNetwork</dc:creator>
      <dc:date>2024-10-21T06:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating GP users to Prisma Access with user certificates?</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/610162#M879</link>
      <description>&lt;P&gt;Yes. Check logs for failed username and passwords, add the source IP's\ranges to the embargo and watch them disappear.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 15:44:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/authenticating-gp-users-to-prisma-access-with-user-certificates/m-p/610162#M879</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-10-21T15:44:19Z</dc:date>
    </item>
  </channel>
</rss>

