<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: global protect: keeping clientless vpn users seperate from remote access (vpn client) users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-keeping-clientless-vpn-users-seperate-from-remote/m-p/257717#M92267</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for contributing to the Education Help Center discussion board.&amp;nbsp; Since this is non-courseware, certification or Learning Center related technical question, I recommend contacting&amp;nbsp;the&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/custom/page/page-id/Support" target="_blank" rel="noopener"&gt;Support team&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;for assistance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;James&lt;/P&gt;</description>
    <pubDate>Tue, 16 Apr 2019 17:49:31 GMT</pubDate>
    <dc:creator>jamesyim</dc:creator>
    <dc:date>2019-04-16T17:49:31Z</dc:date>
    <item>
      <title>global protect: keeping clientless vpn users seperate from remote access (vpn client) users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-keeping-clientless-vpn-users-seperate-from-remote/m-p/257534#M92266</link>
      <description>&lt;P&gt;Here's what I need:&lt;/P&gt;&lt;P&gt;Employees using the global protect client, and vendors logging into clientless vpn and getting the apps I assign them.&lt;/P&gt;&lt;P&gt;I do not want any vendor to be able to access the vpn client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's where I am:&lt;/P&gt;&lt;P&gt;I have a GP portal and gateway assigned to the outside interface. Remote access (employees) authenticates to radius server (ACS) and the people using the client can log in and work fine. Using the same GP portal I set up clientless and published apps and that works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem:&lt;/P&gt;&lt;P&gt;1. In the app publishing setup it has a section for authorizing who is authorized for which app group. Default shows my domain and "All Users" group in AD. Where is it getting that? If I'm using radius for authentication, the radius server authenticates and looks at a specific folder in AD but the palo wouldn't know that. I thought maybe it was using LDAP auth profile or something so I put in the full AD path (cn,ou,dc..etc) but that didn't work at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. I don't know how to differentiate the employees and vendors if the radius server (ACS) policy is based on where the authentication traffic comes from. Both employee and vendor requests would originate from the same place and it won't know which is which.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note:&lt;/P&gt;&lt;P&gt;I'm using ACS as a radius server but it then talks to our RSA server. We use dual factor authentication for anyone using VPN.&lt;/P&gt;&lt;P&gt;No straight LDAP authentication is allowed. However LDAP authorization after the 2 factor radius authentication would be fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a design guide covering using remote access along side clientless access but keeping them seperate? Seems like this would be a very common design.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2019 11:38:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-keeping-clientless-vpn-users-seperate-from-remote/m-p/257534#M92266</guid>
      <dc:creator>daveshreve</dc:creator>
      <dc:date>2019-04-13T11:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: global protect: keeping clientless vpn users seperate from remote access (vpn client) users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-keeping-clientless-vpn-users-seperate-from-remote/m-p/257717#M92267</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for contributing to the Education Help Center discussion board.&amp;nbsp; Since this is non-courseware, certification or Learning Center related technical question, I recommend contacting&amp;nbsp;the&amp;nbsp;&lt;STRONG&gt;&lt;A href="https://live.paloaltonetworks.com/t5/custom/page/page-id/Support" target="_blank" rel="noopener"&gt;Support team&lt;/A&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;for assistance.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 16 Apr 2019 17:49:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-keeping-clientless-vpn-users-seperate-from-remote/m-p/257717#M92267</guid>
      <dc:creator>jamesyim</dc:creator>
      <dc:date>2019-04-16T17:49:31Z</dc:date>
    </item>
  </channel>
</rss>

