<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local user authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39537#M29003</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticating to the firewall works on the firewall management interface and we do not create rules for this interface.&lt;/P&gt;&lt;P&gt;The rules created are for data ports. If a user is traversing through the PAN between 2 zones and the security rule has http and https only allowed as services then that user can only pass port 80 and 443 traffic between the zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Sep 2013 19:12:44 GMT</pubDate>
    <dc:creator>Phoenix</dc:creator>
    <dc:date>2013-09-17T19:12:44Z</dc:date>
    <item>
      <title>Local user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39536#M29002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does it mean if I create a rule that allows http/https services only for authenticated users from local user database between 2 zones? Will the users have to authenticate to the firewall first? How? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Peter&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 19:01:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39536#M29002</guid>
      <dc:creator>peterpan13888</dc:creator>
      <dc:date>2013-09-17T19:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Local user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39537#M29003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authenticating to the firewall works on the firewall management interface and we do not create rules for this interface.&lt;/P&gt;&lt;P&gt;The rules created are for data ports. If a user is traversing through the PAN between 2 zones and the security rule has http and https only allowed as services then that user can only pass port 80 and 443 traffic between the zones.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 19:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39537#M29003</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-09-17T19:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Local user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39538#M29004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Peter,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall administration (logging and authenticating to the firewall to gain WebUi and CLI access) is done under Device &amp;gt; Administrators. We need to manually add administrators. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a user-ip mapping comes to the firewall with a username matched to the one in the local database, then traffic would hit that rule allowing http/https service. One scenario you could think of if by using local database as authentication profile in global protect. It really boils down to where you are using local database as an authentication profile on your Palo Alto firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 19:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39538#M29004</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-17T19:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: Local user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39539#M29005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1243" data-externalid="" data-presence="null" data-userid="21427" data-username="peterpan13888" href="https://live.paloaltonetworks.com/people/peterpan13888"&gt;peterpan13888&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In policy there are only 4 options to configure users "any", "known", "unknown" and "select".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my knowledge there is no option to configure policy for "local user database", because "local user database" is design only firewall authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please provide me more information how did you configure "local user database in policy". I would appreciate if you can share few screen shots.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 19:14:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39539#M29005</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2013-09-17T19:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Local user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39540#M29006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually I am trying to migrate some rules in Juniper firewall and found two that cannot be migrated which allow only locally authenticated users to connect between 2 zones. I just wonder how I can implement the same rules in PA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Sep 2013 20:01:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39540#M29006</guid>
      <dc:creator>peterpan13888</dc:creator>
      <dc:date>2013-09-17T20:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Local user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39541#M29007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Create a Policy between the two zones for "known User" or if you like specific named User. This Policy will only match for authenticated Users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Create Local User Accounts, (you can also use AD User)&lt;/P&gt;&lt;P&gt;Create a Captive Portal Policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1159"&gt;How to Configure Captive Portal&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Marco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Sep 2013 08:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/local-user-authentication/m-p/39541#M29007</guid>
      <dc:creator>ExclusiveNetworksGermany</dc:creator>
      <dc:date>2013-09-18T08:10:04Z</dc:date>
    </item>
  </channel>
</rss>

