<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting specific AD groups to only specific IP addresses on Globalprotect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298291#M78179</link>
    <description>&lt;P&gt;If you have the groups selected in group mapping "Group Include List" then simply add this group to the source user section of a policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I may have assumed too much here but if so then just let us know and we can go back a step or 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Nov 2019 16:15:30 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2019-11-13T16:15:30Z</dc:date>
    <item>
      <title>Restricting specific AD groups to only specific IP addresses on Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298276#M78177</link>
      <description>&lt;P&gt;So I'm going to preface this with the fact that I am not a network admin.&amp;nbsp; Ours quit, so I was basically thrown this stuff.&amp;nbsp; I have only ever done webfiltering on the palo alto.&lt;/P&gt;&lt;P&gt;I got global protect vpn setup using the help of a system engineer.&amp;nbsp; We do the LDAP stuff for webfiltering and for vpn access.&amp;nbsp; Users have to be a member of a specific group to be able to connect.&amp;nbsp; That all works fine.&lt;/P&gt;&lt;P&gt;Problem is now they want me to set it up so that specific groups (other then just standard vpn users) are able to connect, but can only access certain things, mainly specific ip addresses.&lt;/P&gt;&lt;P&gt;How do I do that?&amp;nbsp; Sorry for the vagueness.&amp;nbsp; I've been thrown to the wolves and don't really know what I'm doing.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 15:53:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298276#M78177</guid>
      <dc:creator>GregoryClark</dc:creator>
      <dc:date>2019-11-13T15:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting specific AD groups to only specific IP addresses on Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298291#M78179</link>
      <description>&lt;P&gt;If you have the groups selected in group mapping "Group Include List" then simply add this group to the source user section of a policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I may have assumed too much here but if so then just let us know and we can go back a step or 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 16:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298291#M78179</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-13T16:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting specific AD groups to only specific IP addresses on Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298292#M78180</link>
      <description>&lt;P&gt;or 5, or 7.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 16:16:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298292#M78180</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-13T16:16:29Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting specific AD groups to only specific IP addresses on Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298301#M78183</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your ok with groups then you could do the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User Groups.....&lt;/P&gt;&lt;P&gt;GP user group.&amp;nbsp; &amp;nbsp;this group has all GP users in it. (you already use this for GP for connection)&lt;/P&gt;&lt;P&gt;GP server group. this group contains all users allowed to access servers.&lt;/P&gt;&lt;P&gt;GP FTP group. this group allows users to access ftp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then create address objects for server IP's&amp;nbsp; &amp;nbsp;and FTP IP's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so GP portal will allow GP user group to connect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy 1. allow GP server group access to server IP's&lt;/P&gt;&lt;P&gt;Policy 2 allow GP FTP group access to FTP IP's&lt;/P&gt;&lt;P&gt;Policy 3 allow GP user group access to all common factors, DNS, Internet etc...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 16:41:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298301#M78183</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-13T16:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting specific AD groups to only specific IP addresses on Globalprotect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298385#M78200</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Let us know how we can help! Here is a link to the admin guide for using user-id.&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-web-interface-help/user-identification/device-user-identification-group-mapping-settings.html" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-web-interface-help/user-identification/device-user-identification-group-mapping-settings.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A lot of us use it extensively and can certainly help you out. The hardest thing is to remember the order of your policies so that it takes affect without getting denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Super high level steps:&lt;/P&gt;&lt;P&gt;Create your AD group in AD&lt;/P&gt;&lt;P&gt;Add AD group to PAN&lt;/P&gt;&lt;P&gt;Create policy that uses the AD group and specify destination such as Mick pointed out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 23:19:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/restricting-specific-ad-groups-to-only-specific-ip-addresses-on/m-p/298385#M78200</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-11-13T23:19:19Z</dc:date>
    </item>
  </channel>
</rss>

