<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect VPN Unique ID's and one user allowed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202096#M59658</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a requirement for the following and short of any draconian methods, I'm hoping that the PA GP will be able to answer.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are PAN8.0.7 on 5520's in Active/Passive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a req to ensure that a user of GP is only allowed one GP session at a time.&amp;nbsp; No sharing sessions or passwords.&amp;nbsp; Options explored inlude a unique ldap group or unique tunnel to every user.&amp;nbsp; This will scale poorly and create a nigthmare for management.&amp;nbsp; Is there a better way?&amp;nbsp; I've seen one thread discussing a Feature Request #4603 but I dont see any public ledger for this&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Along with that, I'm looking for a way to generate a unique user ID per vpn session.&amp;nbsp; I see there are timestamps for logins but these are granular to HHMMSS. I've chekced with PA TAC that they cannot be modified to display miliseconds, so using this as a unique ID is a hard sell, so I'd like to see a proper implementation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm totally ready ti move to 8.1.0 when available, perhaps this release has the capabilities if not already there?&lt;/P&gt;</description>
    <pubDate>Fri, 23 Feb 2018 23:17:39 GMT</pubDate>
    <dc:creator>Solomonsands</dc:creator>
    <dc:date>2018-02-23T23:17:39Z</dc:date>
    <item>
      <title>Global Protect VPN Unique ID's and one user allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202096#M59658</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a requirement for the following and short of any draconian methods, I'm hoping that the PA GP will be able to answer.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are PAN8.0.7 on 5520's in Active/Passive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a req to ensure that a user of GP is only allowed one GP session at a time.&amp;nbsp; No sharing sessions or passwords.&amp;nbsp; Options explored inlude a unique ldap group or unique tunnel to every user.&amp;nbsp; This will scale poorly and create a nigthmare for management.&amp;nbsp; Is there a better way?&amp;nbsp; I've seen one thread discussing a Feature Request #4603 but I dont see any public ledger for this&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Along with that, I'm looking for a way to generate a unique user ID per vpn session.&amp;nbsp; I see there are timestamps for logins but these are granular to HHMMSS. I've chekced with PA TAC that they cannot be modified to display miliseconds, so using this as a unique ID is a hard sell, so I'd like to see a proper implementation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm totally ready ti move to 8.1.0 when available, perhaps this release has the capabilities if not already there?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 23:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202096#M59658</guid>
      <dc:creator>Solomonsands</dc:creator>
      <dc:date>2018-02-23T23:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect VPN Unique ID's and one user allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202103#M59659</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83714"&gt;@Solomonsands&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So far this is still not possible. You can vote for the FR, but at the moment thats all - unfortunately.&lt;/P&gt;&lt;P&gt;There is an (ugly) workaround with kicking out users that are logged in more than once, but thats not what what you're searching for.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Remo&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2018 23:39:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202103#M59659</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-23T23:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect VPN Unique ID's and one user allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202104#M59660</link>
      <description>Your suggested solution would be satisfactory, actually. Is There a knowledge base or article available to aid me in configuring this?&lt;BR /&gt;&lt;BR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;</description>
      <pubDate>Sat, 24 Feb 2018 00:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202104#M59660</guid>
      <dc:creator>Solomonsands</dc:creator>
      <dc:date>2018-02-24T00:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect VPN Unique ID's and one user allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202105#M59661</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83714"&gt;@Solomonsands&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I know there is no knowledgebase article for this. This is a workaround I created by myself and also used on our GP gateways, because we also did not want to have the same users logged in more than once.&lt;/P&gt;&lt;P&gt;Anyway what I did is writing this powershell script. This script can then run every 10s, 30, 60s or whatever you chose. Every time the script runs, it checks the logged in users and if a user is logged in more than once only the current session remains and the other GP sessions will be terminated.&lt;/P&gt;&lt;P&gt;As I said ... ugly ... but for me it was sufficient, maybe also for you ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: I deleted the script here because I created a ned topic specially for this:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/How-to-limit-concurrent-GlobalProtect-connections-per-user/m-p/202128#M59665" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/How-to-limit-concurrent-GlobalProtect-connections-per-user/m-p/202128#M59665&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 11:10:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202105#M59661</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-02-24T11:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect VPN Unique ID's and one user allowed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202107#M59662</link>
      <description>Got it. Makes sense to just use the API instead. I can't use MS systems in my environment so this will have to be re written for bash or python. Thank for the perspective</description>
      <pubDate>Sat, 24 Feb 2018 00:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-vpn-unique-id-s-and-one-user-allowed/m-p/202107#M59662</guid>
      <dc:creator>Solomonsands</dc:creator>
      <dc:date>2018-02-24T00:40:56Z</dc:date>
    </item>
  </channel>
</rss>

