<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can I set NAC with Mac address or device information in Pan-OS? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-set-nac-with-mac-address-or-device-information-in-pan-os/m-p/538105#M110510</link>
    <description>&lt;P&gt;I would like to set up NAC for people who bring personal laptops into the company.&lt;BR /&gt;Is it possible to control by linking Mac address and IP, or to assign IP only to authorized devices, or to enable network use?&lt;/P&gt;
&lt;P&gt;Or, can you tell me how to use certificates to prevent network access from devices without root certificates?&lt;/P&gt;</description>
    <pubDate>Mon, 10 Apr 2023 08:34:57 GMT</pubDate>
    <dc:creator>HilineISP_Tech</dc:creator>
    <dc:date>2023-04-10T08:34:57Z</dc:date>
    <item>
      <title>Can I set NAC with Mac address or device information in Pan-OS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-set-nac-with-mac-address-or-device-information-in-pan-os/m-p/538105#M110510</link>
      <description>&lt;P&gt;I would like to set up NAC for people who bring personal laptops into the company.&lt;BR /&gt;Is it possible to control by linking Mac address and IP, or to assign IP only to authorized devices, or to enable network use?&lt;/P&gt;
&lt;P&gt;Or, can you tell me how to use certificates to prevent network access from devices without root certificates?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 08:34:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-set-nac-with-mac-address-or-device-information-in-pan-os/m-p/538105#M110510</guid>
      <dc:creator>HilineISP_Tech</dc:creator>
      <dc:date>2023-04-10T08:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can I set NAC with Mac address or device information in Pan-OS?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-i-set-nac-with-mac-address-or-device-information-in-pan-os/m-p/538115#M110512</link>
      <description>&lt;P&gt;Hi HilineISP_Tech,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is not possible to my knowledge to implement NAC based on MAC on Palo Alto.&lt;/P&gt;
&lt;P&gt;there is feature request see:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/general-topics/mac-address-based-firewall-policies/td-p/253857" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/general-topics/mac-address-based-firewall-policies/td-p/253857&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is potential workaround maybe to achieve what you want but additional configuration would be needed.&lt;/P&gt;
&lt;P&gt;You can configure DHCP on an interface on the Palo Alto firewall, you can use it for Guest device / BYOD.&lt;/P&gt;
&lt;P&gt;Within the DHCP configuration you can edit the Reserved Address and in there you can add the personal devices/Bring Your Own Device(BYOD)&amp;nbsp; 1) ip address 2) mac address 3) description device/owner.&lt;/P&gt;
&lt;P&gt;Then you can create a security policy based on the IP address in MDHCP/Reserved Address to either allow or deny.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the Certificates, to my knowledge that is only possible when using Globalprotect and utilizing client certificates, but that is not applicable here as you are talking about BYOD/Personal devices in the office.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 12:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-i-set-nac-with-mac-address-or-device-information-in-pan-os/m-p/538115#M110512</guid>
      <dc:creator>Y-alwaysMe</dc:creator>
      <dc:date>2023-04-10T12:01:33Z</dc:date>
    </item>
  </channel>
</rss>

