<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict VPN Users to certain applications in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217233#M62856</link>
    <description>&lt;P&gt;User ID and AD Groups is how we do it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule look like this take for example SSL only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAME, SRC Zone=GlobalProtect, Source Address=IP Range of the GP Clients, Src User: DOMAIN\Group name, DestZone= Internal, Dest Address = Group things they need to access, Application=SSL, Service = Port if necessary.&amp;nbsp; ALLOW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jun 2018 19:38:49 GMT</pubDate>
    <dc:creator>Retired Member</dc:creator>
    <dc:date>2018-06-08T19:38:49Z</dc:date>
    <item>
      <title>Restrict VPN Users to certain applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217208#M62852</link>
      <description>&lt;P&gt;Is there a way to restrict some VPN users to only be able to access some applications (ports / servers)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 17:21:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217208#M62852</guid>
      <dc:creator>jcalvert</dc:creator>
      <dc:date>2018-06-08T17:21:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VPN Users to certain applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217232#M62855</link>
      <description>&lt;P&gt;Absolutely.&lt;/P&gt;&lt;P&gt;Palo is using positive enforcement&amp;nbsp; model - everything that is not permitted is blocked by default.&lt;/P&gt;&lt;P&gt;Are your VPN using landing in dedicated VPN zone?&lt;/P&gt;&lt;P&gt;Best practice would be to permit based on users/groups what they need.&lt;/P&gt;&lt;P&gt;If you allow any then you have to block things that you don't want those specific users to access.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:20:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217232#M62855</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-06-08T19:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VPN Users to certain applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217233#M62856</link>
      <description>&lt;P&gt;User ID and AD Groups is how we do it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The rule look like this take for example SSL only&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAME, SRC Zone=GlobalProtect, Source Address=IP Range of the GP Clients, Src User: DOMAIN\Group name, DestZone= Internal, Dest Address = Group things they need to access, Application=SSL, Service = Port if necessary.&amp;nbsp; ALLOW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:38:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217233#M62856</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2018-06-08T19:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VPN Users to certain applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217254#M62860</link>
      <description>&lt;P&gt;This is very helpful.&amp;nbsp; We haven't implemented UserID yet, any way to do this with local users?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 21:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217254#M62860</guid>
      <dc:creator>jcalvert</dc:creator>
      <dc:date>2018-06-08T21:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict VPN Users to certain applications</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217255#M62861</link>
      <description>&lt;P&gt;I assume that by VPN you mean GlobalProtect.&lt;/P&gt;&lt;P&gt;Sure you can use local users. GlobalProtect will identify users and you can see them in Monitor &amp;gt; Traffic under Source User Tab.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jun 2018 21:49:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restrict-vpn-users-to-certain-applications/m-p/217255#M62861</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2018-06-08T21:49:53Z</dc:date>
    </item>
  </channel>
</rss>

