<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block access to internet based on User name and group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/68092#M39795</link>
    <description>&lt;P&gt;Thanks for the information! We are going to hold this in reserve. At least we know that it is feasably possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are speaking to one of the regional municipalities about their in house solution. It seems they have made something like this that we may possibly "copy and paste".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wouldn't that be great if it worked &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a good weekend.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2015 08:58:29 GMT</pubDate>
    <dc:creator>ABAdmin</dc:creator>
    <dc:date>2015-11-13T08:58:29Z</dc:date>
    <item>
      <title>How to block access to internet based on User name and group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/67664#M39629</link>
      <description>&lt;P&gt;We have a request from our teachers for a way to block access to the internet based on students' username.Oh - and the teacher needs to be able to grant or deny this access from a simple interface...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Myself and my colleague are scratching our heads on this one.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What we are thinking is of trying to leverage Active Directory Groups in our PAN and have a simple GUI that would a teacher can edit and which would post a command through to the PAN to grant or deny access for the student\ class group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am wondering if using the PAN CLI (with the User-Agent) would be able to accomplish this... Or if custom ACLs would be better.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone created something similar for use in education? A way for teachers to have direct access via a 3rd party interface and set permissions for a student or group?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any tips and information is GREATLY appreciated!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 18:01:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/67664#M39629</guid>
      <dc:creator>ABAdmin</dc:creator>
      <dc:date>2015-11-04T18:01:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to block access to internet based on User name and group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/67672#M39630</link>
      <description>&lt;P&gt;You can use LDAP look up from you PA to get group from AD.&lt;/P&gt;
&lt;P&gt;Have look on the Admin guide&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-LDAP-Server-Profile/ta-p/58689" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-LDAP-Server-Profile/ta-p/58689&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 21:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/67672#M39630</guid>
      <dc:creator>RC-BHF</dc:creator>
      <dc:date>2015-11-04T21:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to block access to internet based on User name and group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/67675#M39631</link>
      <description>&lt;P&gt;So to expand on what has already been suggested, with respect to AD groups. This is possible and I have done this in the past very successfully. The tricky part comes in where you need to have the teachers modify the groups. You could create an AD group and allow the teachers to be the owners, that way they can just do this on their own. However this is scary if this is a shared group (I wouldnt do this). Where I have done this in the past, the Support Desk (tier1) techs could do this based on tickets. That way there was a record and accountability. Regardless of what the teachers would like, I would be very worried about giving them access to modify an AD group. Perhaps the override feature could be used on false positives? But that password gets spead like wildfire. Or instead of a block page they could get a continue page and then the teacher could request alternative access? This way class is not halted and order is maintained.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 22:59:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/67675#M39631</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-11-04T22:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to block access to internet based on User name and group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/68092#M39795</link>
      <description>&lt;P&gt;Thanks for the information! We are going to hold this in reserve. At least we know that it is feasably possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are speaking to one of the regional municipalities about their in house solution. It seems they have made something like this that we may possibly "copy and paste".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Wouldn't that be great if it worked &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have a good weekend.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2015 08:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-block-access-to-internet-based-on-user-name-and-group/m-p/68092#M39795</guid>
      <dc:creator>ABAdmin</dc:creator>
      <dc:date>2015-11-13T08:58:29Z</dc:date>
    </item>
  </channel>
</rss>

