<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Please suggest about mac-address control in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/217686#M62954</link>
    <description>&lt;P&gt;Hi expert ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know about suggest mac-control because&amp;nbsp; my customer&amp;nbsp; use Fortinet which use device control&amp;nbsp; &amp;nbsp;and I will replace and migrate&amp;nbsp; to Palo-alto if that possible about control this thing .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jun 2018 08:48:26 GMT</pubDate>
    <dc:creator>Pattarachai</dc:creator>
    <dc:date>2018-06-13T08:48:26Z</dc:date>
    <item>
      <title>Please suggest about mac-address control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/217686#M62954</link>
      <description>&lt;P&gt;Hi expert ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to know about suggest mac-control because&amp;nbsp; my customer&amp;nbsp; use Fortinet which use device control&amp;nbsp; &amp;nbsp;and I will replace and migrate&amp;nbsp; to Palo-alto if that possible about control this thing .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 08:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/217686#M62954</guid>
      <dc:creator>Pattarachai</dc:creator>
      <dc:date>2018-06-13T08:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Please suggest about mac-address control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/217736#M62965</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/81046"&gt;@Pattarachai&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Like they're using mac-control to hand out IPs to their network on the Fortinet? It's been a while since I worked on anything Fortinet but I&amp;nbsp;&lt;EM&gt;thought&amp;nbsp;&lt;/EM&gt;that this was on the Fortigate and it was specific to the wireless side of things, but that could have changed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally this is something that you would configure on the LAN via your switches; I'm not sure why someone would have ever configured this to work directly on the firewall unless this is a very small office. Regardless it's something that you&amp;nbsp;&lt;EM&gt;can&lt;/EM&gt; do on the firewall as long as the firewall is handing out the IP addresses, but there's a better way of doing this. Since the firewall can do user identification you can easily run GlobalProtect within the LAN and simply not allow any communication if the ip in question doesn't have an active user-mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the customer is dead set on controlling things via a mac address then set it up correctly and do it on their switches, don't do it on the firewall. If you implement something like this on the firewall there isn't anything stopping someone from wreaking havic across a local switch, because they never have to go through the firewall to do so.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 13:21:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/217736#M62965</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-13T13:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Please suggest about mac-address control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/217759#M62973</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/81046"&gt;@Pattarachai&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The short answer is: no this cannot be done the same way as on the fortinet. As already mentionned by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;there are other ways to achieve kind of the same with paloalto, but the main difference because this is not possible is that paloalto does not produce switching hardware, what fortinet does with dedicated switches and integrated switching modules on their UTM firewalls. It depends on how this is done today but this is a job for a switch (for what your customer now probably uses the fortinet, right?)&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jun 2018 15:51:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/217759#M62973</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-13T15:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: Please suggest about mac-address control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/218053#M63045</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I would suggest looking into user-id based access. I think it is a better method since it is more flexible. You can always use IP address and have the DHCP server check the mac's?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jun 2018 14:22:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/218053#M63045</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-06-15T14:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: Please suggest about mac-address control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/218132#M63057</link>
      <description>&lt;P&gt;Assuming Fortinet uses 802.1x controls for this you could replace that part with another vendor like Aruba and feed the associations over to the PAN device when they are created.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jun 2018 14:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/218132#M63057</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2018-06-16T14:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Please suggest about mac-address control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/218448#M63141</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, I suggest customer deploy User-ID-Agent already Thank you so much, everyone&amp;nbsp; for suggest to me&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 02:34:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/please-suggest-about-mac-address-control/m-p/218448#M63141</guid>
      <dc:creator>Pattarachai</dc:creator>
      <dc:date>2018-06-20T02:34:28Z</dc:date>
    </item>
  </channel>
</rss>

