<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Allow only certain users through VPN Security Policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-certain-users-through-vpn-security-policy/m-p/486565#M104616</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you describe you actual configuration a bit more? Do the users authenticate too VPN with the local users? If they utilize the local users to authenticate to the VPN, as long as you have user-id enable on your VPN zone (and do make sure you do), then this should work without any issues.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what you've described you either aren't authenticating to the VPN as these local users so they aren't mapping, or you simply don't have your VPN security zone User-ID enabled (or included in your include networks).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 May 2022 01:27:56 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-05-12T01:27:56Z</dc:date>
    <item>
      <title>Allow only certain users through VPN Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-certain-users-through-vpn-security-policy/m-p/486286#M104590</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;How can I allow only certain users to use this policy from below? I am not able to do so at the moment using a local database (is it not achievable with a local database?). Currently, only when choosing 'any' will allow traffic through.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="paragkarki143_0-1652249613154.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40945i5C8ABB0C93FBC007/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="paragkarki143_0-1652249613154.png" alt="paragkarki143_0-1652249613154.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 06:38:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-only-certain-users-through-vpn-security-policy/m-p/486286#M104590</guid>
      <dc:creator>Pras</dc:creator>
      <dc:date>2022-05-11T06:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Allow only certain users through VPN Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-certain-users-through-vpn-security-policy/m-p/486372#M104601</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Just to clarify:&lt;/P&gt;
&lt;P&gt;- Users are able to connect to GlobalProtect (GP clients says "connected"), but no traffic is allowed?&lt;/P&gt;
&lt;P&gt;- Stupid question but - you are sure that the local users are addedd to the local user group?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest to check the following:&lt;/P&gt;
&lt;P&gt;- Connect the user with GP&lt;/P&gt;
&lt;P&gt;- Connecting with SSH to FW, use the following command to list ip-to-user mapping.&lt;/P&gt;
&lt;P&gt;&amp;gt; show user ip-user-mapping&lt;/P&gt;
&lt;P&gt;- Find what IP address is associated with the test user that is currently connected to GP and check details for this IP&lt;/P&gt;
&lt;P&gt;&amp;gt; show user ip-user-mapping ip &amp;lt;ip-address&amp;gt;&lt;/P&gt;
&lt;P&gt;- Do you see anything listed under Grourp(s) in the output?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2022 14:38:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-only-certain-users-through-vpn-security-policy/m-p/486372#M104601</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-05-11T14:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: Allow only certain users through VPN Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-only-certain-users-through-vpn-security-policy/m-p/486565#M104616</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/202203"&gt;@Pras&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Can you describe you actual configuration a bit more? Do the users authenticate too VPN with the local users? If they utilize the local users to authenticate to the VPN, as long as you have user-id enable on your VPN zone (and do make sure you do), then this should work without any issues.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From what you've described you either aren't authenticating to the VPN as these local users so they aren't mapping, or you simply don't have your VPN security zone User-ID enabled (or included in your include networks).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 01:27:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-only-certain-users-through-vpn-security-policy/m-p/486565#M104616</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-05-12T01:27:56Z</dc:date>
    </item>
  </channel>
</rss>

