<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allow mobile phone access by userid, is this possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/allow-mobile-phone-access-by-userid-is-this-possible/m-p/43610#M32005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our techs often interface with Zenoss, and we have a mobile app that will let us view and interact with the alarms. The problem is we need to establish VPN access first. I also don't want to open the port for the world, and I can't allow a specific ip/range because they will be connecting from various mobile carriers. I'd like to specify an allowed user as part of the rule, but how can I ensure that mobile device will be allowed via user? Can I create a rule for certificate based authentication? Any other ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Mar 2015 13:49:59 GMT</pubDate>
    <dc:creator>mcocat</dc:creator>
    <dc:date>2015-03-02T13:49:59Z</dc:date>
    <item>
      <title>Allow mobile phone access by userid, is this possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-mobile-phone-access-by-userid-is-this-possible/m-p/43610#M32005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our techs often interface with Zenoss, and we have a mobile app that will let us view and interact with the alarms. The problem is we need to establish VPN access first. I also don't want to open the port for the world, and I can't allow a specific ip/range because they will be connecting from various mobile carriers. I'd like to specify an allowed user as part of the rule, but how can I ensure that mobile device will be allowed via user? Can I create a rule for certificate based authentication? Any other ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2015 13:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-mobile-phone-access-by-userid-is-this-possible/m-p/43610#M32005</guid>
      <dc:creator>mcocat</dc:creator>
      <dc:date>2015-03-02T13:49:59Z</dc:date>
    </item>
    <item>
      <title>Re: Allow mobile phone access by userid, is this possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-mobile-phone-access-by-userid-is-this-possible/m-p/43611#M32006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I understand is you have VPN connection and you want specific users to use mobile devices to access resources. &lt;SPAN style="font-size: 13.3333330154419px;"&gt; If you are using LDAP based authentication, then create a separate user id and group for mobile users. And &lt;/SPAN&gt;create a Global Protect Portal with the user group for mobile users and select Android and iOS under OS. This way only when the both conditions are true, then the VPN will be established.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Let me know if don't like this idea.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2015 21:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-mobile-phone-access-by-userid-is-this-possible/m-p/43611#M32006</guid>
      <dc:creator>jthakur</dc:creator>
      <dc:date>2015-03-02T21:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Allow mobile phone access by userid, is this possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/allow-mobile-phone-access-by-userid-is-this-possible/m-p/43612#M32007</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not exactly. I'd prefer not to VPN at all. For&amp;nbsp; example, I'd like to create a rule that allowed ANY source from the outside to my internal server on port 80, but only for certain users. I know I can create a rule and specify users, but an iphone that doesn't VPN in won't provide user-id matches to the PAN. After doing some research I believe this is an impossible task, but if anyone has some ideas I'd be interested in hearing them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Mar 2015 21:49:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/allow-mobile-phone-access-by-userid-is-this-possible/m-p/43612#M32007</guid>
      <dc:creator>mcocat</dc:creator>
      <dc:date>2015-03-02T21:49:22Z</dc:date>
    </item>
  </channel>
</rss>

