<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect company pc and user pc in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160997#M52441</link>
    <description>&lt;P&gt;That would be correct. Since you only want to allow it on non-corporate computers you'll have to do some testing to see what you can identify on and verify that the machine actually isn't corporate issued.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2017 14:30:55 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-06-13T14:30:55Z</dc:date>
    <item>
      <title>Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/159677#M52149</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a working GP setup. I have setup the agent to be always on, prelogon and auto login when the user logs in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No I want to use the same setup to allow users at home to setup their PC so they can connect,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do want to use the global protect agentm but I don't want it on all the time&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I do this with the same gateway / portal setup ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And how! &amp;nbsp;I presume I use HIP objects and look for domain, but ....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 11:11:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/159677#M52149</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-06-06T11:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/159840#M52170</link>
      <description>&lt;P&gt;Can you give more details when you say " I have a working GP setup"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am looking for more details like, is this an External set up or an internal setup. In short is the portal accesible only from inside your &amp;nbsp;organization or from anywhere.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 17:32:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/159840#M52170</guid>
      <dc:creator>SuryaR</dc:creator>
      <dc:date>2017-06-06T17:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/159911#M52189</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have PA-3060 in Active /Active cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Portal assigned to a loopback address - with a Highly available IP floating , bound to primary&lt;/P&gt;&lt;P&gt;I have 2 external gateways assigned to loopbacks on the PA - 1 on each node&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setup for alway on in the Portal, using certificates stored currently only in the machine cert store&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have an internal gateway but thats mainly for people using internal wifi.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My agent is condigured to do pre-logon and then do a SSO login with the users windows username and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is all fine for all the corporate users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I would like to allow some users (mainly developers) the ability to connect from home - or remotely and not have always on, but on demand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This would need to be made on computer not user name&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 21:37:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/159911#M52189</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-06-06T21:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160413#M52293</link>
      <description>&lt;P&gt;Thank you for detail explanation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"But I would like to allow some users (mainly developers) the ability to connect from home - or remotely and not have always on, but on demand."&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will these users use your organization assets to connect or their own/personal machines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 14:16:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160413#M52293</guid>
      <dc:creator>SuryaR</dc:creator>
      <dc:date>2017-06-09T14:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160419#M52295</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/62286"&gt;@Alex_Samad&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Considering that you want to do this specifically through computer info instead of user-id the only way you could do this is with another gateway and add specific HIP checking to specify something unique to these computers and have the rights to check that information. Likely you would want to do this through hostname.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 15:10:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160419#M52295</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-09T15:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160479#M52307</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just for clarity and to make sure I understand as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setup GP for company assets and we mandate always on, so pre logon and auto SSO login with windows login. I believe I have that all setup on GP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My next task was to allow some users - dev - to access the internal network, vpn in . But I didn't want to impose upon them that they needed to have always on, i wanted on by demand.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it seems like the answer is I have to have 2 GP 1 for corporate users and 1 for guest ... non corporate laptop/pc/device&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does that sum it up correctly ?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 22:09:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160479#M52307</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-06-09T22:09:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160997#M52441</link>
      <description>&lt;P&gt;That would be correct. Since you only want to allow it on non-corporate computers you'll have to do some testing to see what you can identify on and verify that the machine actually isn't corporate issued.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 14:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/160997#M52441</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-13T14:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect company pc and user pc</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/161093#M52452</link>
      <description>&lt;P&gt;I saw there was a test in HIP ? I am new to this. &amp;nbsp;which talks about domain I had hoped, that it was talking about MS AD domainm but I am guessing its ip domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do control the certificates, I would just create 2 int CA's 1 for corporate and 1 for non corp. &amp;nbsp;Although that sounds a but hard/extra work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;have to have a play with it some more&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 23:57:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-company-pc-and-user-pc/m-p/161093#M52452</guid>
      <dc:creator>Alex_Samad</dc:creator>
      <dc:date>2017-06-13T23:57:41Z</dc:date>
    </item>
  </channel>
</rss>

