Deny internet access by OS

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Deny internet access by OS

L1 Bithead

hi there,

is there a possibility to create a rule to deny internet acces by specific os?

i want to disconnect a large set windows xp clients from the internet, but allow access fo win7 clients.

thank you

sascha

1 accepted solution

Accepted Solutions

L4 Transporter

Hello Sascha,

Refer the doc,

GlobalProtect Configuration Tech Note

Look for "Host Information Objects and Profiles" section in the above doc which explains the details and information about configuration as needed to block users based on identifying the user pc OS name and details.

Note: This feature needs Portal and Gateway license.

Thanks

View solution in original post

2 REPLIES 2

L7 Applicator

This is possible through HIP objects/profiles using Global Protect which lets you query the client for different information such as OS type etc. This information is then fed back to the firewall by the GP client and a HIP object/profile can be used in a security rule to match on this information.

L4 Transporter

Hello Sascha,

Refer the doc,

GlobalProtect Configuration Tech Note

Look for "Host Information Objects and Profiles" section in the above doc which explains the details and information about configuration as needed to block users based on identifying the user pc OS name and details.

Note: This feature needs Portal and Gateway license.

Thanks

  • 1 accepted solution
  • 2583 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!