I am being asked if GlobalProtect could be locked down to only except a specific list of MAC addresses (our corporate laptops) only.
I see information about Device Block list or HIP configuration. I don't really want to specify a block list, but rather an allow list and block everything else.
Is that possible?
We using PA 3020 with 7.1.15.
Ok, gotcha. Thanks @Mick_Ball
Would this be along side (separately) from the existing wildcard we use for our GlobalProtect Gateway SSL/TLS profile?
Or instead of?
As I am thinking...sounds like could be instead of. Could use "local" certificates rather than one like GoDaddy that every device has a CA root cert for.
Thank you! @Mick_Ball
Looks like I can follow this documentation.
I have a test environment to prove this out. I'll close this now, update it later.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!