<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setting Restricted Access to Certain GlobalProtect Users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13255#M9714</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a PA beginner so bare with me. I am trying to restrict access to only a few servers to several of our GlobalProtect VPN users. I could set these users into groups but how would I restrict access for each group? We have a PA-500 with 5.0.6 OS version. Let me know if any other info is needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Dec 2013 21:08:29 GMT</pubDate>
    <dc:creator>TroyFlex</dc:creator>
    <dc:date>2013-12-16T21:08:29Z</dc:date>
    <item>
      <title>Setting Restricted Access to Certain GlobalProtect Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13255#M9714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am a PA beginner so bare with me. I am trying to restrict access to only a few servers to several of our GlobalProtect VPN users. I could set these users into groups but how would I restrict access for each group? We have a PA-500 with 5.0.6 OS version. Let me know if any other info is needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Dec 2013 21:08:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13255#M9714</guid>
      <dc:creator>TroyFlex</dc:creator>
      <dc:date>2013-12-16T21:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Restricted Access to Certain GlobalProtect Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13256#M9715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Troy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to have separate gateways configured for the different groups in the GP Portal configuration, and then in the Gateway configuration, you would restrict access to the particular users of a group using the access routes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whatever networks you configure in the Access Route section of the Client Configuration (Gateway) are the only resources that the users in the particular group have access to.&lt;/P&gt;&lt;P&gt;This would be a split tunnel for your users where traffic to these configured networks/servers would route through the VPN tunnel, and the rest of their regular internet traffic would go out through their traditional default gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;tasonibare&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Dec 2013 21:31:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13256#M9715</guid>
      <dc:creator>tasonibare</dc:creator>
      <dc:date>2013-12-16T21:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Restricted Access to Certain GlobalProtect Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13257#M9716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;A href="https://live.paloaltonetworks.com/u1/25617"&gt;troyflex&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is to find best way to restrict or control access to the users who are connecting through GP to internal resources.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;gt; So some users(User-set A ) should have access to only few servers and other set of users( User-set B) should have access to all. GP tunnel should be ending in a VPN zone. If GP is configured directly into Trust zone we cannot use the flexibility of security rules.&lt;/P&gt;&lt;P&gt;In the security rules add the rule1 -&amp;gt; to have just the User-set A to access to the few servers. Users can be made as a local group, or just add those user IPs in the security rule. Make a rule2 -&amp;gt; For User-set B where they have access to all. By doing so we are providing specific access to each group. Remember always have specific rule in the top and more generic rule at the bottom while designing security rules.&lt;/P&gt;&lt;P&gt;2&amp;gt; If we have Ldap groups configured on the PAN then we can create security rules with just for selected users to access servers by giving the User-id in the rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this is clear !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 00:06:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13257#M9716</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-12-17T00:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Restricted Access to Certain GlobalProtect Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13258#M9717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies! Phoenix, it looks like GP is part of our Trust Zone. So what I would have to do is remove GP from the Trust Zone and create a zone just for the GP VPN and then I would be able to apply access rules to the user groups? Let me know if I have that right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tasonibare, we might not have enough gateways for all the different groups we are going to have. To be clear, when I configure another gateway, I need to have another external IP address to set as that gateway? Let me knowif I am correct in assuming this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help, guys.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Troy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 20:59:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13258#M9717</guid>
      <dc:creator>TroyFlex</dc:creator>
      <dc:date>2013-12-17T20:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Setting Restricted Access to Certain GlobalProtect Users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13259#M9718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Troyflex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right, that is exact !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Dec 2013 21:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/setting-restricted-access-to-certain-globalprotect-users/m-p/13259#M9718</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2013-12-17T21:28:10Z</dc:date>
    </item>
  </channel>
</rss>

