<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131755#M46977</link>
    <description>&lt;P&gt;I want the users in the client1 group to be only able to connect to their client portal and not be able to use the portals for client2, 3 or 4.&amp;nbsp; I think that I am going try to setup 4 different profiles running differnet ports then 1812 for each group.&lt;/P&gt;</description>
    <pubDate>Wed, 07 Dec 2016 13:51:44 GMT</pubDate>
    <dc:creator>kdingwall</dc:creator>
    <dc:date>2016-12-07T13:51:44Z</dc:date>
    <item>
      <title>More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131492#M46964</link>
      <description>&lt;P&gt;We are hosting 4 clients with each having their own server.&amp;nbsp; I have setup 4 separate GlobalProtect Gateways and Portals for each client with access only to their server.&amp;nbsp; I have configured Radius and tested it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to be able have one different Active Directory group for each client and have the users that are in the respective groups only have access to their GlobalProtect Portal.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 16:29:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131492#M46964</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-06T16:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131535#M46966</link>
      <description>&lt;P&gt;If you only have one Active Directory server for all of these users then it would probably be best to simply change the user groups allowed to login on your GP portal&amp;nbsp;configuration; that would allow you to have a 'client1' group with all of those users assigned and so on for all 4 on the 4 different portals and the other users would not be allowed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 18:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131535#M46966</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-06T18:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131755#M46977</link>
      <description>&lt;P&gt;I want the users in the client1 group to be only able to connect to their client portal and not be able to use the portals for client2, 3 or 4.&amp;nbsp; I think that I am going try to setup 4 different profiles running differnet ports then 1812 for each group.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 13:51:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131755#M46977</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-07T13:51:44Z</dc:date>
    </item>
    <item>
      <title>Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131758#M46979</link>
      <description>&lt;P&gt;So if I understand this correctly you want to limit it so that client1 isn't even able to see the portal for client2 and so on; and not only having client1 not being able to login?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 14:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131758#M46979</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-07T14:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131787#M46982</link>
      <description>&lt;P&gt;I have 4 GlobalProtect Gateways and Portals on different IP address and different FQDNs (client1.domain.com, client2.domain.com, client3.domain.com, client4.domain.com).&amp;nbsp; They are all set to split tunneling and each is limited to accessing only their own server on my network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Radius setup and working.&amp;nbsp; Right now all VPN users for all clients are in one Domain VPN group and can logon to all 4 VPN Portals.&amp;nbsp; I want to have 4 separate Domain VPN groups (One for each client) and have someone in the client1vpn Domain group only be able to connect to the client1.domain.com VPN and someone in the client2vpn Domain group only be able to connect to the client2.domain.com VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These servers have HIPPA data on them and no client is to have access to another client's data.&amp;nbsp; Users from one client cannot logon to another client's server, but my supervisors do not want to be able to connect to another client's VPN.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 16:15:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131787#M46982</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-07T16:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131818#M46984</link>
      <description>&lt;P&gt;You can easily just seperate out who is allowed to login to which portal as already stated. Since you are limiting the connections to client1.domain.com to the client1 IP addresses there is no reason to change ports or anything like that.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 17:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131818#M46984</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-12-07T17:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131886#M46988</link>
      <description>&lt;P&gt;Maybe I am not being clear. &amp;nbsp;I do not want someone that is in the client1 domain group to only be able to authenticate to the the client1 portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With radius there does not seem to be a way to do this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am now trying with LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am now running into another issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I select a specific domain group in the Authentication Profile, I get an Authentication Failed on the client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I select All&amp;nbsp;&lt;SPAN&gt;in the Authentication Profile, it works.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So I am back to square one again.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2016 20:14:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/131886#M46988</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-07T20:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: More than one Radius Connection Profile for GlobalProtect on PAN-OS 7.1.0 and Windows 2012 R2 NP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/132095#M47021</link>
      <description>&lt;P&gt;The LDAP issue was solved by manually typing in the word none in the Username Modifier field.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Dec 2016 15:20:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/more-than-one-radius-connection-profile-for-globalprotect-on-pan/m-p/132095#M47021</guid>
      <dc:creator>kdingwall</dc:creator>
      <dc:date>2016-12-14T15:20:08Z</dc:date>
    </item>
  </channel>
</rss>

