GlobalProtect MAC Address Filter?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

GlobalProtect MAC Address Filter?

L4 Transporter

Hello folks,

 

I am being asked if GlobalProtect could be locked down to only except a specific list of MAC addresses (our corporate laptops) only.  

 

I see information about Device Block list or HIP configuration.  I don't really want to specify a block list, but rather an allow list and block everything else. 

 

Is that possible?

 

 

We using PA 3020 with 7.1.15.

https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/use-host-i...

 

1 accepted solution

Accepted Solutions

It would be along side...

 

also along side your existing authentication method.....

 

so... go daddy for tls profile, ldap or sso or local user or 2 factor auth plus device cert to only allow known devices.

 

your challenge will be to distribute certs...

 

can be done via Group policy..

 

 

View solution in original post

6 REPLIES 6

L7 Applicator

Not via mac address but have you considered certifcates...

 

just generate a root CA on your palo and then use this to create device certificates...

Ok, gotcha. Thanks @Mick_Ball

Would this be along side (separately) from the existing wildcard we use for our GlobalProtect Gateway SSL/TLS profile?

 

Or instead of?

 

As I am thinking...sounds like could be instead of.  Could use "local" certificates rather than one like GoDaddy that every device has a CA root cert for.

 

It would be along side...

 

also along side your existing authentication method.....

 

so... go daddy for tls profile, ldap or sso or local user or 2 factor auth plus device cert to only allow known devices.

 

your challenge will be to distribute certs...

 

can be done via Group policy..

 

 

Thank you!  @Mick_Ball

 

Looks like I can follow this documentation.

https://www.paloaltonetworks.com/documentation/71/globalprotect/globalprotect-admin-guide/set-up-the...

 

I have a test environment to prove this out.  I'll close this now, update it later.

Yep, you got it.., if you need any further assistance then jus update this post... 

good luck...

 

laters....

L4 Transporter

I`m using PanOS 10.0.8 and I notice there is no Device Block List for me to select. I want to block a few device mac address to access global protect.

Network > GlobalProtect > Device Block List
 
May I know is is PanOS 10 removed the feature ? 
  • 1 accepted solution
  • 12835 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!