<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to limit global protect for specific android/ios users? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218295#M63112</link>
    <description>&lt;P&gt;You're right this "little" detail was missing in my post. But you could solve this with a dedicated global protect gateway for the iOS/Android devices.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Jun 2018 21:20:39 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-06-18T21:20:39Z</dc:date>
    <item>
      <title>How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218241#M63093</link>
      <description>&lt;P&gt;I have an interesting scenario. We have windows users accessing global protect. I am looking to buy gateway license to enable a set of users(10) out of 400 users to use android/iphone to connect to vpn. We&amp;nbsp; have IBM MaaS360 MDM installed on phone to collect mobile attributes. Is there a way I can enforce a policy to limit specific users to use mobile phones?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your help is greatly appreciated. TIA&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 16:20:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218241#M63093</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-06-18T16:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218260#M63096</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;There is actually a few different places that you could do something like this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) You could build out a special Authentication Profile specific to a group that is allowed to login via mobile devices and set the GlobalProtect Portal 'Authentication' Client Auth settings to include an entry that specifically lists the OS as [ Android iOS WindowsUWP ] and limit the other Client Auth settings specific to [ Browser Linux Mac ] and any user not included in the new profile simply couldn't auth if they attempted to utilize a mobile client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This option would limit the Auth from a Portal perspective.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) You could do the exact same thing but from the Gateway Auth page.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You could take it a step further and utilize a HIP check and the Agent Client Settings but that gets messy and isn't really required if you do either of the two options above.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 16:37:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218260#M63096</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-06-18T16:37:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218261#M63097</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) There are two ways you could do this, limit the OS in the portal agent configs section&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="portal config.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15519i086308DB4638998A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="portal config.png" alt="portal config.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;b) with GP gateway license you can enforce policy upon HIP objects. one HIP object is moible device model&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="hip.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15520iE973F1D046FED7B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="hip.png" alt="hip.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/host-information/configure-hip-based-policy-enforcement" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/globalprotect/globalprotect-admin-guide/host-information/configure-hip-based-policy-enforcement&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 16:38:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218261#M63097</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-18T16:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218264#M63098</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) There are two ways you could do this, limit the OS in the portal agent configs section&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="portal config.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/15519i086308DB4638998A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="portal config.png" alt="portal config.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This probably is the easiest/best way. Here you could specify a usergroup, so only users of that usergroup receive the configuration for Android/iOS devices. Other users will be able to login to the portal actually but cannot connect as they will not receive the required configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you already have an MDM, you don't really need the Gateway license. With the MDM for example you could deploy a client certificate to the specific devices and so only these devices will be able to connect. This does not require the gateway license as you would use the integrated VPN clients on the mobile devices.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 17:53:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218264#M63098</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-18T17:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218288#M63107</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;Thank you so much for your suggestion. We have users authentication against our RADIUS server which utilizes one-time-password. Doing this will require me to configure other auth method(preferably local) but this is not what my organisation is looking for. I am little confused at this point.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:49:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218288#M63107</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-06-18T20:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218289#M63108</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;Shouldn't I need a MDM to get the mobile attributes? We have a cloud based MDM server and unsure if the vendor provides HIP info.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:51:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218289#M63108</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-06-18T20:51:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218290#M63109</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;Your suggestion boils down to authenticating GP users based on client certificates?&amp;nbsp; I dodnot want to make any kind of changes to exisiting windows users and add specific mobile users to exisiting gateway and portal. will this be addressed? Please correct me if I am wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:55:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218290#M63109</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-06-18T20:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218295#M63112</link>
      <description>&lt;P&gt;You're right this "little" detail was missing in my post. But you could solve this with a dedicated global protect gateway for the iOS/Android devices.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 21:20:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218295#M63112</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-18T21:20:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218336#M63119</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70284"&gt;@SThatipelly&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;Shouldn't I need a MDM to get the mobile attributes? We have a cloud based MDM server and unsure if the vendor provides HIP info.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No you don't. The GlobalProtect App that is run on the mobile device is capable of pulling this information - so provided you have the Gateway License you can make full use of this functionality.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/globalprotect/objects-globalprotect-hip-objects" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/80/pan-os/web-interface-help/globalprotect/objects-globalprotect-hip-objects&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Luke.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 08:32:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218336#M63119</guid>
      <dc:creator>LukeBullimore</dc:creator>
      <dc:date>2018-06-19T08:32:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to limit global protect for specific android/ios users?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218354#M63122</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/52796"&gt;@LukeBullimore&lt;/a&gt;&amp;nbsp;I had gone through that document before and found this little note:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To collect mobile device attributes and utilize them in HIP enforcement policies, GlobalProtect requires an MDM server. GlobalProtect currently supports HIP integration with the AirWatch MDM server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is what concerning me.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 12:30:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-limit-global-protect-for-specific-android-ios-users/m-p/218354#M63122</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2018-06-19T12:30:33Z</dc:date>
    </item>
  </channel>
</rss>

