<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-id is it possible to check computers? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-it-possible-to-check-computers/m-p/12467#M9117</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our clients want to know if it is possible to build policies based on computer membership to AD groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this situation we want to differentiate between computers that belongs to AD and which do not in purpose of VPN connections, so that users won't connect from private computers with SSL client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Piotr Bratkowski&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Nov 2011 09:50:19 GMT</pubDate>
    <dc:creator>Support_CC</dc:creator>
    <dc:date>2011-11-21T09:50:19Z</dc:date>
    <item>
      <title>User-id is it possible to check computers?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-it-possible-to-check-computers/m-p/12467#M9117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of our clients want to know if it is possible to build policies based on computer membership to AD groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this situation we want to differentiate between computers that belongs to AD and which do not in purpose of VPN connections, so that users won't connect from private computers with SSL client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Piotr Bratkowski&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Nov 2011 09:50:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-it-possible-to-check-computers/m-p/12467#M9117</guid>
      <dc:creator>Support_CC</dc:creator>
      <dc:date>2011-11-21T09:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-id is it possible to check computers?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-it-possible-to-check-computers/m-p/12468#M9118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently, we only do "user" identification through Active Directory. One option to acheive what you want is to use "Global Protect" feature for all internal and remote users to log in to corporate network. It basically replaces ssl-vpn for remote users. You can configure "Computer Name" under HIP Profile for Global protect users to be identified only when they try to login through that particular computer. Again, there is lot of manual work required for it to work, you need to manually enter each compuetr name under HIP profile and match registery entry realted to that computer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1757"&gt;https://live.paloaltonetworks.com/docs/DOC-1757&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please feel free to contact us if you have question.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Nov 2011 03:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-is-it-possible-to-check-computers/m-p/12468#M9118</guid>
      <dc:creator>snisar</dc:creator>
      <dc:date>2011-11-24T03:09:03Z</dc:date>
    </item>
  </channel>
</rss>

