Configuring PA-500 - separate access to to different IP addresses

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Configuring PA-500 - separate access to to different IP addresses

L0 Member

Hello All,

 

I hope that you can help me with one, I would say, common task but I'm unable to find right answer to this.

We are using PA-500 and behind it, there is 5 servers. We also using Global Protect for accessing to servers.
I need to setup on PA-500 that one specific user need to access only to one specific server, while all other users can access to all servers. I know that should be simple, but I'm stuck with it. I can't find any similar information either in documentation either here.

Any help would be highly appreciated.

Thanks in advance for any help.
Milan

1 REPLY 1

Cyber Elite
Cyber Elite

If you have user identification enabled you can just setup the user as having access to the one server that you actually want them to access by identifying the user in a new rule and putting it above the one in place to allow the GP users access to all of the servers.

Alternatively if you don't have user-id then you could statically give the one user a specific IP address and set a rule that allows that user access to the one server and all other IPs in the GP pool have access to the other servers. 

  • 1592 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!