Personal VPN Services thwarting Company Policies

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Personal VPN Services thwarting Company Policies

L1 Bithead

Downstream of our PAN's, we have our Citrix environment.  This environment includes some Netscalers that have a nice feature in that they provide in their SYSLOG, two fields named "ClientIP" and "NATIP".   This proves quite useful in that while the ClientIP field geolocates to a local Boston IP address, the NATIP address shows they are coming in from, for example, Spain.   While we have rules in our PAN that should prevent these non-US connections, the VPN services apparently use a local proxy that thwarts the PAN's location lookup.

 

I've searched and can't seem to find if the PAN's can present and utilize something equivalent to the Netscaler's NATIP so as to be able to leverage it in a policy rule or not.

 

Note: I have the TOR rules setup but these connections are not TOR.

Any ideas?

Thanks!

16 REPLIES 16

Hello OtakarKlier, I've looked into the use of EDL's but the total number of IP addresses the PAN can support from EDL's is far short of the number of US VPN endpoints currently known.   Given this I have two options:
  • create a web server that can lookup IP addresses accessing our Citrix environment against a list of known VPN endpoints (yes, there are services that maintain a list of known worldwide VPN endpoints), and add matches found to a EDL.
  • Or, figure out how to get the PAN to show the real NATIP as shown above.  A rule that would test  Where SOURCEIP  <> NATIP -> DROP would be all it'd take.

I don't know why a Netscaler can see the real NATIP and a PAN cannot.

Still looking for the answer.

Thanks for kicking this around with me!

Cyber Elite
Cyber Elite

Hello,

I think this is a real scenario that others are facing as well. I reached out to a SE I know really well and he suggested the following:

https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/web-proxy

Not sure of the code version or hardware you are running however.

Regards,

  • 2719 Views
  • 16 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!