<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect User Mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327429#M83326</link>
    <description>&lt;P&gt;I think I understand your question a little better now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there are a number of different ways to do that. I would start by looking at your options in the Config Selection Criteria section of your GlobalProtect Portal Configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network Tab &amp;gt;&amp;gt; GlobalProtect &amp;gt;&amp;gt; Portals &amp;gt;&amp;gt; Click the portal &amp;gt;&amp;gt; Agent tab on the left &amp;gt;&amp;gt; GP Client Config settings &amp;gt;&amp;gt; Config Selection Criteria &amp;gt;&amp;gt; Device Checks or Custom Checks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From there you can assign different portals/profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Ap.&lt;/P&gt;</description>
    <pubDate>Mon, 11 May 2020 22:15:45 GMT</pubDate>
    <dc:creator>andeporter</dc:creator>
    <dc:date>2020-05-11T22:15:45Z</dc:date>
    <item>
      <title>Global Protect User Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/326904#M83236</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have following scenario and unsure how to do it. Please let me know your thoughts:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have VM Palo Alto and we are implementing Global Protect.&lt;/P&gt;&lt;P&gt;The Global Protect Portal and Gateway would be one and the same VM.&lt;/P&gt;&lt;P&gt;We are planning to only have only one VPN link/URL which will be given to our customers.&lt;/P&gt;&lt;P&gt;Now, we are planning to create all the users who will access Global Protect VPN to be created as users in PA Local User Database.&lt;/P&gt;&lt;P&gt;Now,&lt;/P&gt;&lt;P&gt;Customer A has employees a1,a2,a3.. who will access VPN&lt;/P&gt;&lt;P&gt;Customer B has employees b1,b2,...&lt;/P&gt;&lt;P&gt;Customer C has employees c1,c2,c3...&lt;/P&gt;&lt;P&gt;and so on as need grows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now,&lt;/P&gt;&lt;P&gt;Customer A employees can access only 10.1.1.0/24 from our internal network&lt;/P&gt;&lt;P&gt;Customer B employees can access only 10.1.2.0/24 from our internal network&lt;/P&gt;&lt;P&gt;Customer C employees can access only 10.1.3.0/24 from our internal network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can this be done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Do I need different IP pools per customer?&lt;/P&gt;&lt;P&gt;2. Can users be assigned static IP addresses when they connect to VPN? i.e. each time same address?&lt;/P&gt;&lt;P&gt;3. How can I bind users to customers? Or I dont need to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I can do this somewhere in Gateway Config under client settings probably. But need your guidance here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any pointers appreciated.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 06:18:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/326904#M83236</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2020-05-08T06:18:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327107#M83263</link>
      <description>&lt;P&gt;Rjdahav,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems like you have a pretty good handle on how to accomplish this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You've already established that each set of customers will need their own IP address/range pool based on the fact that they all need to have restrictions to separate, internal ranges.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Customer A - Global protect pool of something like 172.16.1.0/24 to 10.1.1.0/24 from our internal network&lt;/P&gt;&lt;P&gt;Customer B - Global protect pool of something like 172.16.2.0/24 to 10.1.2.0/24 from our internal network&lt;/P&gt;&lt;P&gt;Customer C - Global protect pool of something like 172.16.3.0/24 to 10.1.3.0/24 from our internal network&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The control can then be established via the routing setup for each group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can a user get the same IP address via Global Protect each time? Yes, but why would you want/need this?&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIMCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIMCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure what you mean by "bind users to customers". Can you give me a little more background here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Ap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 20:48:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327107#M83263</guid>
      <dc:creator>andeporter</dc:creator>
      <dc:date>2020-05-08T20:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327276#M83292</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/140984"&gt;@andeporter&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can understand, "bind users to customer" is a bit confusing.&lt;/P&gt;&lt;P&gt;I wanted to ask, how will the PA identify that when person a1 logs in, a1 should be given an IP reserved for customer A (&lt;SPAN&gt;172.16.1.0/24 from your reply&lt;/SPAN&gt;)? How would PA know which person belongs to which customer since they will all have same URL to connect to.&lt;/P&gt;&lt;P&gt;I will also start simulating this more in our lab scenario and probably it will be more clear to me.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 10 May 2020 23:58:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327276#M83292</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2020-05-10T23:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327429#M83326</link>
      <description>&lt;P&gt;I think I understand your question a little better now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there are a number of different ways to do that. I would start by looking at your options in the Config Selection Criteria section of your GlobalProtect Portal Configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network Tab &amp;gt;&amp;gt; GlobalProtect &amp;gt;&amp;gt; Portals &amp;gt;&amp;gt; Click the portal &amp;gt;&amp;gt; Agent tab on the left &amp;gt;&amp;gt; GP Client Config settings &amp;gt;&amp;gt; Config Selection Criteria &amp;gt;&amp;gt; Device Checks or Custom Checks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From there you can assign different portals/profiles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Ap.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 22:15:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327429#M83326</guid>
      <dc:creator>andeporter</dc:creator>
      <dc:date>2020-05-11T22:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327494#M83345</link>
      <description>perhaps i have not understood your question but why not do this via a policy. source users a1,a2,a3 destination 10.1.1.0/24 allow source users b1,b2,b3 destination 10.1.2.0/24 allow source users c1,c2,c3 destination 10.1.3.0/24 allow and just have one ip pool for all users...</description>
      <pubDate>Tue, 12 May 2020 08:39:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-user-mapping/m-p/327494#M83345</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2020-05-12T08:39:41Z</dc:date>
    </item>
  </channel>
</rss>

