<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to allow only one connection per user-ID in the Palo Alto firewall? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538203#M110519</link>
    <description>&lt;P&gt;Basically, it is a state in which multiple users can be connected when User-ID is created.&lt;BR /&gt;How can I make this so that only one person can access a single User-ID?&lt;BR /&gt;You cannot build additional servers like LDAP, SAML, Kerberos, etc...&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 05:55:39 GMT</pubDate>
    <dc:creator>HilineISP_Tech</dc:creator>
    <dc:date>2023-04-11T05:55:39Z</dc:date>
    <item>
      <title>Is it possible to allow only one connection per user-ID in the Palo Alto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538203#M110519</link>
      <description>&lt;P&gt;Basically, it is a state in which multiple users can be connected when User-ID is created.&lt;BR /&gt;How can I make this so that only one person can access a single User-ID?&lt;BR /&gt;You cannot build additional servers like LDAP, SAML, Kerberos, etc...&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 05:55:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538203#M110519</guid>
      <dc:creator>HilineISP_Tech</dc:creator>
      <dc:date>2023-04-11T05:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to allow only one connection per user-ID in the Palo Alto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538221#M110523</link>
      <description>&lt;P&gt;You can create by creating a username and password and ensure that has a unique name so that it doesn't conflict. and enable user-id and this will allow the firewall to identify users and their ip address ,map the usernames with ip addresses in User Agent-ID.set or create the access policies like what are the actions that need to be allowed to that particular user.&lt;/P&gt;
&lt;P&gt;note:the main thing is that the user should rely on keeping the credentials secure by not sharing to anybody.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 09:57:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538221#M110523</guid>
      <dc:creator>ABBASALI.S</dc:creator>
      <dc:date>2023-04-11T09:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to allow only one connection per user-ID in the Palo Alto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538234#M110528</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/240427"&gt;@HilineISP_Tech&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The easiest path to accomplish this is to enforce GlobalProtect from client machines on the network and then use a script to ensure that each user-id is only ever associated once. There's a script example that&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;shared years ago &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-concurrent-globalprotect-connections-per-user/td-p/202128" target="_self"&gt;HERE&lt;/A&gt;&amp;nbsp;that uses the API to ensure only a single mapping.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem that you'll run into if you don't use an enforced GlobalProtect connection is that there's certain situations where we'd expect to see someone map to multiple IPs. Keeping in mind that user-id isn't a User-&amp;gt;IP mapping but rather an IP-&amp;gt;User mapping, if you have an environment where someone would get a different IP address when they move around the building(s) having the user associated temporarily with multiple IPs wouldn't be unexpected.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 12:43:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538234#M110528</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2023-04-11T12:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to allow only one connection per user-ID in the Palo Alto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538340#M110538</link>
      <description>&lt;P&gt;It was the answer I was looking for.&lt;BR /&gt;Thanks so much for the link to the example&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 01:10:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/538340#M110538</guid>
      <dc:creator>HilineISP_Tech</dc:creator>
      <dc:date>2023-04-12T01:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to allow only one connection per user-ID in the Palo Alto firewall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/596337#M118636</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know that this is an old post but I would like to share an update for anyone looking for a solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In order to achieve that I created a external &amp;amp; standalone program to limit concurrent GlobalProtect sessions/connections per unique user. &lt;SPAN class="HwtZe"&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;It can be accessed here&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;:&amp;nbsp; &lt;A href="https://github.com/enginy88/PAN-GPLimiter" target="_blank"&gt;https://github.com/enginy88/PAN-GPLimiter&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;This topic also discussed here: &lt;A href="https://live.paloaltonetworks.com/t5/general-topics/pan-gplimiter-limit-concurrent-globalprotect-sessions/td-p/596293" target="_blank"&gt;https://live.paloaltonetworks.com/t5/general-topics/pan-gplimiter-limit-concurrent-globalprotect-sessions/td-p/596293&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:10:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-it-possible-to-allow-only-one-connection-per-user-id-in-the/m-p/596337#M118636</guid>
      <dc:creator>enginy</dc:creator>
      <dc:date>2024-08-29T18:10:59Z</dc:date>
    </item>
  </channel>
</rss>

