<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect - blocking single user account in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/99084#M44166</link>
    <description>&lt;P&gt;We want to use an authentication profile that matches against&amp;nbsp;a fairly generic LDAP AD group in the Allow list tab. Is there a way of&amp;nbsp;creating exceptions to the allow list for blocking individual user accounts from using the service, should we need to at any stage?&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jul 2016 09:15:38 GMT</pubDate>
    <dc:creator>aceandy79</dc:creator>
    <dc:date>2016-07-21T09:15:38Z</dc:date>
    <item>
      <title>GlobalProtect - blocking single user account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/99084#M44166</link>
      <description>&lt;P&gt;We want to use an authentication profile that matches against&amp;nbsp;a fairly generic LDAP AD group in the Allow list tab. Is there a way of&amp;nbsp;creating exceptions to the allow list for blocking individual user accounts from using the service, should we need to at any stage?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 09:15:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/99084#M44166</guid>
      <dc:creator>aceandy79</dc:creator>
      <dc:date>2016-07-21T09:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - blocking single user account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/99898#M44220</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If I understand your inquiry correctly, yes you can block a single user. You would obviously need to have one of the user-id options available so scan for that users id. When it comes to the policies, make the more specific one higher prirority than the general one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;Security policy to block the single user&lt;/P&gt;&lt;P&gt;Security policy to allow everyone else&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 15:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/99898#M44220</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-07-25T15:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - blocking single user account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/99942#M44222</link>
      <description>&lt;P&gt;Otakar.Klier is correct; as long as you have the deny entry further above your allow entry then it would work perfectly fine and any user-id identified in your deny list is denied.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 18:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/99942#M44222</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-07-25T18:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - blocking single user account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/100406#M44251</link>
      <description>&lt;P&gt;Hi, yes I agree a security policy rule using the User-ID column can be used to block the traffic of a connected client, but the key here is that would only take effect after they've connected. What I was hoping to be able to achieve is to prevent a specific user authenticating in the first place, who is a member of the larger AD group referenced in the Allowed List.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I can tell, the initating packets to set up the IPSec tunnel do not include a User-ID at this point, you only start seeing that column populated after the tunnel is established.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 14:40:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/100406#M44251</guid>
      <dc:creator>aceandy79</dc:creator>
      <dc:date>2016-07-26T14:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - blocking single user account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/100479#M44261</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So you do not wish for them to connect to the VPN? Perhaps I am not understanding your question properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise,&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 17:06:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/100479#M44261</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-07-26T17:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - blocking single user account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/100503#M44263</link>
      <description>&lt;P&gt;Okay, then you would need to take them out of your authentification profile under the object tab. Under your LDAP/Radius/Whatever server there is an allow list under the advanced options. It might be worth making a VPN-Allow AD group and putting anyone who needs VPN access under that group, this would keep anybody that is not in that specific AD group access to the VPN gateway.&lt;/P&gt;&lt;P&gt;To my understanding their is no way to do a 'not' statement under this option.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 18:13:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-blocking-single-user-account/m-p/100503#M44263</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-07-26T18:13:12Z</dc:date>
    </item>
  </channel>
</rss>

