<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius Group for GP authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/576286#M115672</link>
    <description>&lt;P&gt;Any suggestion on the above please? Do i need to configure any Data Redistribution or LDAP server to get that groups checked?&lt;/P&gt;</description>
    <pubDate>Tue, 06 Feb 2024 15:40:15 GMT</pubDate>
    <dc:creator>Sanjay_Ramaiah</dc:creator>
    <dc:date>2024-02-06T15:40:15Z</dc:date>
    <item>
      <title>Radius Group for GP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/574260#M115428</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;We need to setup a specific user group in Radius should only access the GP. No other users should access GP. Currently authentication method set for GP is Radius and in the same radius we need a specific group of users only to authenticate.&lt;/P&gt;
&lt;P&gt;May i know how i can acheive this please? Do i need to setup something like Data Redistribution server config or anything?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 10:03:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/574260#M115428</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-01-24T10:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Group for GP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/574369#M115452</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/249853"&gt;@Sanjay_Ramaiah&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In the authentication profile just add the group/user(s) that you want to allow into the allow list, if the user is not in that group they'll be denied. I'd go a step further and ensure that on your GlobalProtect Gateway under Agent -&amp;gt; Client Settings that you again only have the group/user(s) that you intent to allow. This way you need a misconfiguration in&amp;nbsp;&lt;EM&gt;both&amp;nbsp;&lt;/EM&gt;places to actually have unexpected access to GlobalProtect.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2024 23:00:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/574369#M115452</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-01-24T23:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Group for GP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/574463#M115460</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; this is what i thought, but i have this doubt, if I just update the user group how will Palo firewall knows where to fetch the User Group details from? Or in the Radius configured, instead of All users do i need to give User Group info there as well?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 12:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/574463#M115460</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-01-25T12:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Group for GP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/576286#M115672</link>
      <description>&lt;P&gt;Any suggestion on the above please? Do i need to configure any Data Redistribution or LDAP server to get that groups checked?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 15:40:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-group-for-gp-authentication/m-p/576286#M115672</guid>
      <dc:creator>Sanjay_Ramaiah</dc:creator>
      <dc:date>2024-02-06T15:40:15Z</dc:date>
    </item>
  </channel>
</rss>

