<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL VPN Security in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-security/m-p/25093#M18295</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the SSL VPN setup and working.&amp;nbsp; All my remote users have access to the internal resources they need.&amp;nbsp; The time has now come to add a vendor to access their specific internal server.&amp;nbsp; So, I will create an user on the PA in the Local DB and configure the VPN to allow them to connect.&amp;nbsp; My question is, once they connect and authenticate, how to I control their access to only allow access to a specific IP address?&amp;nbsp; My tunnel in in the trusted zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ken &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Sep 2011 21:14:45 GMT</pubDate>
    <dc:creator>tohoken</dc:creator>
    <dc:date>2011-09-22T21:14:45Z</dc:date>
    <item>
      <title>SSL VPN Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-security/m-p/25093#M18295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the SSL VPN setup and working.&amp;nbsp; All my remote users have access to the internal resources they need.&amp;nbsp; The time has now come to add a vendor to access their specific internal server.&amp;nbsp; So, I will create an user on the PA in the Local DB and configure the VPN to allow them to connect.&amp;nbsp; My question is, once they connect and authenticate, how to I control their access to only allow access to a specific IP address?&amp;nbsp; My tunnel in in the trusted zone.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ken &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Sep 2011 21:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-security/m-p/25093#M18295</guid>
      <dc:creator>tohoken</dc:creator>
      <dc:date>2011-09-22T21:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN Security</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-security/m-p/25094#M18296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have two ways to apply secuirty on SSLVPN traffic in your scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. move the tunnel interface to a dedicated SSLVPN zone, so that all traffic from SSLVPN zone to other zone must be explicitly allowed. And you can apply control based on source users or group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. keep your current setting but creae policy based on the source user or group that you have given to the vendor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can also apply AV, AS and Vul profiles to that policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can review the traffic log and you should see the user id used by the vendor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jones &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Sep 2011 06:22:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-security/m-p/25094#M18296</guid>
      <dc:creator>jleung</dc:creator>
      <dc:date>2011-09-23T06:22:49Z</dc:date>
    </item>
  </channel>
</rss>

