<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking unknown devices that are not within the domain in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-unknown-devices-that-are-not-within-the-domain/m-p/996587#M122391</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;I am a Palo Alto PA-450 user. In our organization, we removed around 20 computers from the domain due to their outdated versions. However, these computers continue to log in using the credentials of the last user who logged in while they were still in the domain. This is not a major issue for us. The problem is that these computers are still accessing the internet. When we investigate using Putty, these devices appear as 'unknown' and are obtaining IP addresses. Is it possible to create a rule in our firewall's policies section to allow only computers within the domain to access the internet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"I used ChatGPT for translations as English is not my native language. I apologize if my sentences are unclear."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Dec 2024 21:01:36 GMT</pubDate>
    <dc:creator>hasanuzun27</dc:creator>
    <dc:date>2024-12-04T21:01:36Z</dc:date>
    <item>
      <title>Blocking unknown devices that are not within the domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-unknown-devices-that-are-not-within-the-domain/m-p/996587#M122391</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;I am a Palo Alto PA-450 user. In our organization, we removed around 20 computers from the domain due to their outdated versions. However, these computers continue to log in using the credentials of the last user who logged in while they were still in the domain. This is not a major issue for us. The problem is that these computers are still accessing the internet. When we investigate using Putty, these devices appear as 'unknown' and are obtaining IP addresses. Is it possible to create a rule in our firewall's policies section to allow only computers within the domain to access the internet?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"I used ChatGPT for translations as English is not my native language. I apologize if my sentences are unclear."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Dec 2024 21:01:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-unknown-devices-that-are-not-within-the-domain/m-p/996587#M122391</guid>
      <dc:creator>hasanuzun27</dc:creator>
      <dc:date>2024-12-04T21:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking unknown devices that are not within the domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-unknown-devices-that-are-not-within-the-domain/m-p/997459#M122479</link>
      <description>&lt;P&gt;the IoT addon license allows you to fetch all your device serials from (among others) Entra ID and apply security based on the device serial&lt;/P&gt;
&lt;P&gt;you can also make DHCP exceptions for the mac addresses of the allowed/decommissioned devices and prevent the outdated devices from joining the network&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 11:44:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-unknown-devices-that-are-not-within-the-domain/m-p/997459#M122479</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-12-10T11:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking unknown devices that are not within the domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-unknown-devices-that-are-not-within-the-domain/m-p/997559#M122488</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;If you have user-id setup, you can create security policies that allow internet access only if the user-id is of a matching domain user. Also set the user-id to a lifetime of like 45 minutes.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2024 21:49:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-unknown-devices-that-are-not-within-the-domain/m-p/997559#M122488</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2024-12-10T21:49:54Z</dc:date>
    </item>
  </channel>
</rss>

