<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Grant access to device with specific installed applications and captive portal for others in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149514#M49800</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if it was possible, and how, to grant&amp;nbsp;access in the internal network (wired and wi-fi), on the basis of the presence of an application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact, I want to allow access to devices where&amp;nbsp;spécific applications are installed, and redirect others to a captive portal for identification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you got any information tu set up this solution ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 25 Mar 2017 12:36:48 GMT</pubDate>
    <dc:creator>informatiq</dc:creator>
    <dc:date>2017-03-25T12:36:48Z</dc:date>
    <item>
      <title>Grant access to device with specific installed applications and captive portal for others</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149514#M49800</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know if it was possible, and how, to grant&amp;nbsp;access in the internal network (wired and wi-fi), on the basis of the presence of an application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In fact, I want to allow access to devices where&amp;nbsp;spécific applications are installed, and redirect others to a captive portal for identification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you got any information tu set up this solution ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2017 12:36:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149514#M49800</guid>
      <dc:creator>informatiq</dc:creator>
      <dc:date>2017-03-25T12:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Grant access to device with specific installed applications and captive portal for others</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149521#M49801</link>
      <description>&lt;P&gt;I'd love to be wrong, but I don't believe so. Being able to detect what's installed on a local machine would require a client of some sort installed on the client (at the very least, a java applet) to be able to scan for a local file/registry key and report back to the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there may be a clumsy, awkward workaround possible using the API and/or EDLs if you can get the detection/reporting component working, through possibly another management client running on the desktop.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Mar 2017 16:52:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149521#M49801</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-03-25T16:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: Grant access to device with specific installed applications and captive portal for others</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149599#M49807</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you think that we could use the Globalprotect client to detect applications ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Globalprotect can do that for VPN client, but I don't know if it works for wired or Wi-Fi access.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 07:37:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149599#M49807</guid>
      <dc:creator>informatiq</dc:creator>
      <dc:date>2017-03-27T07:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Grant access to device with specific installed applications and captive portal for others</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149601#M49809</link>
      <description>&lt;P&gt;GP client can detect which applications users have installed when connecting to GP gateway. So you could make this work with internal GP gateway maybe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA FW can filter traffic based on applications passing through the firewall, but can't make decisioins based on applications installed on client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What you are looking for is usually&amp;nbsp;part of NAC solution (allowing clients netwrok access based on their posture).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 07:51:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149601#M49809</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2017-03-27T07:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Grant access to device with specific installed applications and captive portal for others</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149604#M49811</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For your installed users GlobalProtect could provide HIP checks that allow you to check if certain applications are installed/running and will perform UserID at the same time&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can then simply enable captive portal for the same network, as captive portal will only trigger for non-identified users: anyone without GlobalProtect or the capability of checking if certains applications are installed will be redirected&lt;/P&gt;</description>
      <pubDate>Mon, 27 Mar 2017 07:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/149604#M49811</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-03-27T07:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Grant access to device with specific installed applications and captive portal for others</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/151022#M50055</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I try your solution, but I have problems.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I follow this tutorial :&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/documentation/61/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/globalprotect-for-internal-hip-checking-and-user-based-access" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/globalprotect/globalprotect-admin-guide/globalprotect-quick-configs/globalprotect-for-internal-hip-checking-and-user-based-access&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I made my HIP profile, and I put the (Globalprotect) portal and the (Globalprotect) gateway on my subnet interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In HIP Match logs I don't see any configuration. So I try to connect myself with the Globalprotect client, and there are HIP match in logs.&lt;/P&gt;&lt;P&gt;Moreover, I don't find options to enable captive portal only for non-identified users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also try to make a captive portal without Globalprotect (&lt;EM&gt;Device&lt;/EM&gt;&amp;gt;&lt;EM&gt;User Identification&lt;/EM&gt; and &lt;EM&gt;Policies&lt;/EM&gt;&amp;gt;&lt;EM&gt;Captive Portal&lt;/EM&gt;). But I can't make a rule to use HIP profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you help me on these&amp;nbsp;points?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(The PAN-OS version is 7.1.7)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2017 08:21:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/151022#M50055</guid>
      <dc:creator>informatiq</dc:creator>
      <dc:date>2017-04-04T08:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Grant access to device with specific installed applications and captive portal for others</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/151027#M50057</link>
      <description>&lt;P&gt;by default Captive Portal only triggers for unidentified users&lt;/P&gt;
&lt;P&gt;you can't enable HIP profiles for Captive portal, HIP is only supported on GlobalProtect&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd suggest you focus on one aspect at a time and add more features as you make sure the previous feature works as expected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;start by setting up captive portal&lt;/P&gt;
&lt;P&gt;this should spawn a login page for everyone&lt;/P&gt;
&lt;P&gt;next, set up &lt;STRIKE&gt;captive portal&lt;/STRIKE&gt; GlobalProtect and have these users simply be identified, to ensure your GP users are properly identified and everyone else gets served a captive portal login page&lt;/P&gt;
&lt;P&gt;next, add hip checks to ensure your GP users have the appropriate software installed and running&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this step by step will considerably simplify your efforts to make things work as expected&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;::edited::&lt;/P&gt;</description>
      <pubDate>Thu, 04 May 2017 13:34:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/grant-access-to-device-with-specific-installed-applications-and/m-p/151027#M50057</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-05-04T13:34:11Z</dc:date>
    </item>
  </channel>
</rss>

