<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication for educational site, before being controlled by PAN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24632#M17942</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if you've found a solution yet, but what you are describing sounds like Network Access Control.&amp;nbsp; I don't know if Palo Alto recommends any particular NAC vendor, but there are several out there.&amp;nbsp; Usually these solutions will do exactly what you are looking for: Identify user/machine based on your choice of credentials then place them in the correct VLAN (the NAC product does this by communicating directly with the LAN switch).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple I'd recommend checking out:&lt;/P&gt;&lt;P&gt;Bradford Networks (&lt;SPAN class="f"&gt;&lt;CITE&gt;&lt;A href="http://www.bradfordnetworks.com"&gt;www.&lt;STRONG&gt;bradfordnetworks&lt;/STRONG&gt;.com&lt;/A&gt;)&lt;/CITE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Forescout (&lt;A href="http://www.forescout.com"&gt;www.forescout.com&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck!&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Jul 2010 04:40:13 GMT</pubDate>
    <dc:creator>abarnett</dc:creator>
    <dc:date>2010-07-22T04:40:13Z</dc:date>
    <item>
      <title>Authentication for educational site, before being controlled by PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24629#M17939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I'm after is a system that acts as a RADIUS server to authenticate&amp;nbsp; both wired and wireless users over the network via EAP. The network will&amp;nbsp; then authenticate the user and allow them access to specific VLANs,&amp;nbsp; depending on the user and what machine they are logged on to.&lt;BR /&gt; &lt;BR /&gt;Some possible scenarios:&lt;BR /&gt;Staff Member without admin rights:&lt;BR /&gt;-&amp;nbsp; If they logon to a School-managed Library fixed PC, they should get&amp;nbsp; access to the Staff-Managed VLAN.&lt;BR /&gt;- If they logon to an unmanaged&amp;nbsp; personal laptop that they've brought in from home, they should get&amp;nbsp; access to the Staff-Unmanaged VLAN.&lt;BR /&gt; &lt;BR /&gt;Student without admin rights:&lt;BR /&gt;- If they logon to a School -managed Library fixed PC, they should get access to the&amp;nbsp; Student-Managed VLAN.&lt;BR /&gt;- If they logon to their assigned School-managed student laptop, they should get access to the&amp;nbsp; Student-Managed VLAN.&lt;BR /&gt; - If they logon to another School-managed student laptop, they should&amp;nbsp; be disallowed access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Student with admin rights on their&amp;nbsp; Kristin-managed student laptop only:&lt;BR /&gt;- If they logon to a School-managed Library fixed PC, they should get access to the&amp;nbsp; Student-Managed VLAN.&lt;BR /&gt; - If they logon to their assigned School-managed student laptop (with&amp;nbsp; admin rights), they should get access to the Student-SemiManaged VLAN.&lt;BR /&gt;-&amp;nbsp; If they logon to another School-managed student laptop, they should be&amp;nbsp; disallowed access.&lt;BR /&gt; - If they logon to an unmanaged personal laptop that they've brought in&amp;nbsp; from home, they should get access to the Student-Unmanaged VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guest&amp;nbsp; who has registered with School:&lt;BR /&gt;- If they logon to a School-managed Library fixed PC, they should get access to the Guest&amp;nbsp; VLAN.&lt;BR /&gt; - If they logon to an unmanaged personal laptop that they've brought in,&amp;nbsp; they should get access to the Guest VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Intruder who hasn't&amp;nbsp; registered with School:&lt;BR /&gt;- If they logon to any personal laptop, and&amp;nbsp; try to plug in to our network, they should be disallowed access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Up to 1/2 of the student owned systems will be Apple Macs, just to make things interesting.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The RADIUS server will use something like PEAP/EAP-MSCHAPv2. On School-managed machines joined to the School AD domain, the&amp;nbsp; authentication will happen automatically and the user won't have to&amp;nbsp; enter any usernames/passwords. For an unmanaged machine, the user will&amp;nbsp; be prompted to enter their AD username and password (or a guest username&amp;nbsp; and password).&lt;BR /&gt; &lt;BR /&gt;So we would need to have info on the user (mainly coming from AD)&amp;nbsp; and the device they are connecting from. We'd need to either be able to&amp;nbsp; point the RADIUS server at an existing database, or be able to&amp;nbsp; automatically sync the RADIUS server database with our asset database or&amp;nbsp; CMDB.&lt;BR /&gt; &lt;BR /&gt; We also need to be able to get the log information of which user was&amp;nbsp; logged on to which MAC address (real time), so that we can convert this&amp;nbsp; to an IP address via DHCP logs,&amp;nbsp; and then send the IP-to-user info to Palo Alto. We don't want a user on&amp;nbsp; their unmanaged&amp;nbsp; home machine entering a password once for the RADIUS server, then again&amp;nbsp; for Palo Alto's captive&amp;nbsp; portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suppose we are most similar to a tertiary network in the US where&amp;nbsp; students bring in their&amp;nbsp; own devices and enter a&lt;BR /&gt; username and password to be allowed on to the network, before something&amp;nbsp; like Palo Alto takes over and does firewalling of appropriate content.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone know of a solution that is capable of this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 00:36:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24629#M17939</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2010-04-29T00:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication for educational site, before being controlled by PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24630#M17940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for providing your requirements in details. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If those groups of devices (School-managed Library fixed PCs, unmanaged&amp;nbsp; personal laptops, School-managed student laptops, etc) are separated by IP subnets or VLANs, then it is very likely that Palo Alto Networks can help meet your needs. If not, some network changes may be required.&amp;nbsp; However, it is best that you contact your Palo Alto sales team for the design to ensure success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some of your requests can be administered at the machine PCs/Macs levels.&amp;nbsp; For examples:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Student without admin rights:&lt;/P&gt;&lt;P&gt;if they logon to another School-managed student laptop, they should&amp;nbsp; be disallowed access. &lt;/P&gt;&lt;P&gt;A: you can restrict the account login of each assigned student machine to the specific student &amp;amp; nwk admins only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Student with admin rights on their&amp;nbsp; Kristin-managed student laptop only:&lt;/P&gt;&lt;P&gt;If they logon to another School-managed student laptop, they should be&amp;nbsp; disallowed access.&lt;/P&gt;&lt;P&gt;A: Same as above, you can restrict the account login of each assigned student machine to the specific student &amp;amp; nwk admins only.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Apr 2010 02:30:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24630#M17940</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2010-04-29T02:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication for educational site, before being controlled by PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24631#M17941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So thats actually the problem. Due to the dynamic nature of the environment, its getting the device to authenticate to the correct VLAN that is causing us a headache.&lt;/P&gt;&lt;P&gt;Once the VLAN is assigned its plain sailing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SteveR&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2010 09:42:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24631#M17941</guid>
      <dc:creator>KatanaNZ</dc:creator>
      <dc:date>2010-05-04T09:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication for educational site, before being controlled by PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24632#M17942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if you've found a solution yet, but what you are describing sounds like Network Access Control.&amp;nbsp; I don't know if Palo Alto recommends any particular NAC vendor, but there are several out there.&amp;nbsp; Usually these solutions will do exactly what you are looking for: Identify user/machine based on your choice of credentials then place them in the correct VLAN (the NAC product does this by communicating directly with the LAN switch).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A couple I'd recommend checking out:&lt;/P&gt;&lt;P&gt;Bradford Networks (&lt;SPAN class="f"&gt;&lt;CITE&gt;&lt;A href="http://www.bradfordnetworks.com"&gt;www.&lt;STRONG&gt;bradfordnetworks&lt;/STRONG&gt;.com&lt;/A&gt;)&lt;/CITE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Forescout (&lt;A href="http://www.forescout.com"&gt;www.forescout.com&lt;/A&gt;)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good luck!&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 04:40:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24632#M17942</guid>
      <dc:creator>abarnett</dc:creator>
      <dc:date>2010-07-22T04:40:13Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication for educational site, before being controlled by PAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24633#M17943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree - looks like a NAC product is required.&lt;/P&gt;&lt;P&gt;You can then tie the NAC into Palo Alto's User-ID.&amp;nbsp; So long as the Radius server used for EAP/PEAP has the user and IP credentials, it can then feed this information into the XML API of the User-ID Agent.&amp;nbsp; So you end up with NAC and also IAC &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Jul 2010 10:43:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-for-educational-site-before-being-controlled-by/m-p/24633#M17943</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-07-22T10:43:13Z</dc:date>
    </item>
  </channel>
</rss>

