<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect : Need a VPN that separates users into different VLANs; is this possible w/o Panorama? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-need-a-vpn-that-separates-users-into-different/m-p/123450#M46228</link>
    <description>&lt;P&gt;I need my client VPN to support different vlans based upon authentication to either Microsoft NPS or LDAP groups.&lt;BR /&gt;I want a different vlan/IP assigned to the user depending on which group in Active Directory they are in.&lt;BR /&gt;&lt;BR /&gt;Is this configuration possible without purchasing Panorama?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 02 Nov 2016 22:05:25 GMT</pubDate>
    <dc:creator>andersone</dc:creator>
    <dc:date>2016-11-02T22:05:25Z</dc:date>
    <item>
      <title>GlobalProtect : Need a VPN that separates users into different VLANs; is this possible w/o Panorama?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-need-a-vpn-that-separates-users-into-different/m-p/123450#M46228</link>
      <description>&lt;P&gt;I need my client VPN to support different vlans based upon authentication to either Microsoft NPS or LDAP groups.&lt;BR /&gt;I want a different vlan/IP assigned to the user depending on which group in Active Directory they are in.&lt;BR /&gt;&lt;BR /&gt;Is this configuration possible without purchasing Panorama?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Nov 2016 22:05:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-need-a-vpn-that-separates-users-into-different/m-p/123450#M46228</guid>
      <dc:creator>andersone</dc:creator>
      <dc:date>2016-11-02T22:05:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect : Need a VPN that separates users into different VLANs; is this possible w/o Panor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-need-a-vpn-that-separates-users-into-different/m-p/123849#M46253</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Gateway configuraiton, you can assign the client configuration to apply specifically to a group of users. In the client configuartion, you can choose the IP pool and the access route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Network &amp;gt; GlobalProtect &amp;gt; Gateways &amp;gt; Agent &amp;gt; Client Settings&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="body_table"&gt;User/User Group tab&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="body_table"&gt;Specify the user or user group and client operating system to which this agent configuration applies.&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="body_table"&gt;User/User Group&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="body_table"&gt;&lt;SPAN class="GUI_Screen_Text"&gt;Add&lt;/SPAN&gt; a specific user or user group to which this configuration applies.&lt;/DIV&gt;&lt;DIV class="body_table"&gt;&lt;SPAN class="Bold"&gt;Note&lt;/SPAN&gt;: You must configure group mapping (&lt;SPAN class="GUI_Screen_Text"&gt;Device &amp;gt; User Identification &amp;gt; Group Mapping Settings&lt;/SPAN&gt;) before you can select users and groups.&lt;/DIV&gt;&lt;DIV class="body_table"&gt;You can also create configurations that are deployed to agents or apps in &lt;SPAN class="GUI_Screen_Text"&gt;pre-logon&lt;/SPAN&gt;mode (before the user logs in to the endpoint) or configurations to deploy to &lt;SPAN class="GUI_Screen_Text"&gt;any&lt;/SPAN&gt;user.&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Furthermore, when the user connects to GlobalProtect, the firewall will save the user to IP mapping, you can simply configure security policies based on the user group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure how Panorama is relevant here, you can do the above with or without Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Haytham&lt;/P&gt;</description>
      <pubDate>Thu, 03 Nov 2016 21:23:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-need-a-vpn-that-separates-users-into-different/m-p/123849#M46253</guid>
      <dc:creator>hzayed</dc:creator>
      <dc:date>2016-11-03T21:23:33Z</dc:date>
    </item>
  </channel>
</rss>

