<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authenticating external users to firewall like Sonicwall? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41704#M30682</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typing wan ip to a browser.....&lt;/P&gt;&lt;P&gt;users are outside on the internet ? or inside just guest....solution will depend on their position...&lt;/P&gt;&lt;P&gt;Captive Portal looks like a suitable solution for that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Sep 2013 12:01:33 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2013-09-22T12:01:33Z</dc:date>
    <item>
      <title>Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41701#M30679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am configuring a PA-500 for a POC exercise with a customer who is currently using a Sonicwall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While there are obviously other/better ways to accomplish this and I realize how silly this is, given the limited scope I'm presently working in, I need to find a way to replicate a feature they presently "require".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Sonicwall world, a user outside the corporate network can browse to the WAN IP of the firewall and log in with their credentials to become a "Trusted User" on the firewall.&amp;nbsp; A firewall rule applying only to "Trusted Users" then allows them to RDP to a different IP in their /28 which gets NAT-ed through to a Remote Desktop server on the inside.&amp;nbsp; Kind of a "Captive Portal in reverse", I guess.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to replicate this functionality as closely as possible in PAN world??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks!&lt;/P&gt;&lt;P&gt;--jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Sep 2013 01:56:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41701#M30679</guid>
      <dc:creator>SmartEdgeJC</dc:creator>
      <dc:date>2013-09-22T01:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41702#M30680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jeff,&lt;/P&gt;&lt;P&gt;You can set up and customize a captive portal to direct user authentication by way of an authentication &lt;SPAN style="font-size: 10pt;"&gt;profile&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;, an authentication sequence, or a client certificate profile. Captive portal can be used in conjunction &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;with&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; the User-ID Agent to extend user identification functions beyond the Active Directory domain. &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;Users are directed to the portal and authenticated, thereby creating a user-to-IP address mapping.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Also&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;If the user cannot be identified based on login information, an established session or client probe, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;the&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; firewall can redirect any outbound HTTP requests and redirect the user to a web form. The web &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;form&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; can transparently authenticate the user through &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;SPAN class="GINGER_SOFATWARE_correct"&gt;a&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; NTLM challenge, which is &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;automatically &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;evaluated&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; and answered by the web-browser or through an explicit login page.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Sep 2013 07:22:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41702#M30680</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2013-09-22T07:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41703#M30681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If these users need connect from the outside/internet, enabling CP on WAN interface would be taxing for the firewall resources. &lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Only alternative that I can think of is using Global Protect configured with External Gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Users can connect to GP portal/gateway and authenticate using their AD/Radius/Kerberos/Local DB&amp;nbsp; credentials and would be assigned an IP from the configured IP pool.&lt;/P&gt;&lt;P&gt;Security policies can be configured between the tunnel zone and Inside zone to access the RDP server.&lt;/P&gt;&lt;P&gt;Plus....GP (1Portal + 1Gateway ) does not need licenses starting OS_4.1.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH..!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Sep 2013 09:58:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41703#M30681</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-09-22T09:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41704#M30682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typing wan ip to a browser.....&lt;/P&gt;&lt;P&gt;users are outside on the internet ? or inside just guest....solution will depend on their position...&lt;/P&gt;&lt;P&gt;Captive Portal looks like a suitable solution for that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Sep 2013 12:01:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41704#M30682</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-22T12:01:33Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41705#M30683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Outside on the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;--jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 09:47:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41705#M30683</guid>
      <dc:creator>SmartEdgeJC</dc:creator>
      <dc:date>2013-09-23T09:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41706#M30684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I imagine that if they buy this thing after the POC that they'll be deploying GP, but sadly for now I have to figure out how to do this without otherwise it isn't going to fly......................&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 09:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41706#M30684</guid>
      <dc:creator>SmartEdgeJC</dc:creator>
      <dc:date>2013-09-23T09:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41707#M30685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The use case here is for some employees with Macs to be able to log into the terminal server from home.&amp;nbsp; I'm told that connecting a Mac to a Sonicwall can be a pain in the backside.&amp;nbsp; Obviously GP works on OS X, and I bet the built in VPN client would work fine as well... but the preference at this point is to rock the boat as little as possible to get the blue device in the door.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I considered throwing it in in vwire mode but one of their pain points is how pokey the Sonicwall is with all the security features turned on.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 10:01:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41707#M30685</guid>
      <dc:creator>SmartEdgeJC</dc:creator>
      <dc:date>2013-09-23T10:01:23Z</dc:date>
    </item>
    <item>
      <title>Re: Authenticating external users to firewall like Sonicwall?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41708#M30686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;VWIRE mode with following settings should be a good way to start.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;gt; All the tags allowed 0-4094&lt;/P&gt;&lt;P&gt;2&amp;gt;Non-Syn-tcp-reject&amp;nbsp; turned off&lt;/P&gt;&lt;P&gt;3&amp;gt;assymetric bypass tuned on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These settings would ensure that PA&amp;nbsp; functions as a transparent device, staying inline.&lt;/P&gt;&lt;P&gt;Security features can be selectively turned on an ad hoc basis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-HTH...!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Sep 2013 10:27:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticating-external-users-to-firewall-like-sonicwall/m-p/41708#M30686</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-09-23T10:27:40Z</dc:date>
    </item>
  </channel>
</rss>

