Block a specific MAC address to be barred from connecting through our Global protect VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Block a specific MAC address to be barred from connecting through our Global protect VPN

L3 Networker

Hi Team,

 

We have a query whether we can able to block a specific device from Connecting our Global Protect VPN by using the Device MAC Address.

 

Please review and share us with your thoughts. Awaiting for your reply !!

 

Best Regards,

Sahul Hameed

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

@SahulH,

Not via MAC address. You would do this by creating an entry within the Device Block List and specifying the Host ID and Hostname of the blocked endpoint. 

View solution in original post

9 REPLIES 9

Cyber Elite
Cyber Elite

@SahulH,

Not via MAC address. You would do this by creating an entry within the Device Block List and specifying the Host ID and Hostname of the blocked endpoint. 

Hi @BPry ,

 

Thanks for your response. How do I get the Host ID information from a Machine to configure the Device Block List.

 

Also one more query is that, do we need to a have any specific subscription for using Device Block List feature in PA Firewall.

 

Best Regards,

Sahul Hameed

@SahulH,

The Host ID field is visible in the GlobalProtect logs (I don't know if this is a default field, so you may have to view detailed logs or simply select it so it's visible). You don't need a GlobalProtect subscription to have the ability to use this feature. 

@BPry ,

 

Thanks for your respose. I will check on this and will share you with the outcome shortly. 

 

Best Regards,

Sahul Hameed

@BPry ,

 

Under Global Protect Logs we are unable to get the Host-ID information for Linux based machines. So is this related to Licensing. Since we don't have a valid subscription for GP gateway. Please share your thoughts. 

 

Best Regards,

Sahul Hameed

@SahulH,

If you don't have a GlobalProtect subscription then your Linux agents are using X-Auth instead of the actual GlobalProtect agent. In that case, a Host ID isn't generated and you don't have a clear cut way to block any one particular endpoint. 

@BPry ,

 

Thanks for your response !!

 

Best Regards,

Sahul Hameed

@BPry ,

 

Query 1 --> Whether can we able to see the logs for the user machine which we have blocked using the Host-ID in case if they try to connect to the Global Protect?.

 

Query 2 --> Also in Global Protect logs, for some of the MAC and Windows machine Host-ID information is not captured by the Agent what will be the possible cause for this and how to resolve this . 

 

Snap for Host ID not captured for some and captured for some for the same machine itself:

 

SahulH_0-1614947467578.png

 

Please let us know if you have thoughts on this below mentioned queries. Awaiting for your response !!

 

Best Regards,

Sahul Hameed

 

Hi @BPry ,

 

Any inputs on my 2nd query because i found out the answer for the 1st query. 

 

I am still waiting get an inputs from you for my 2nd query. Please review and share something on this. Awaiting for your response !!

 

Best Regards,

Sahul Hameed

 

 

  • 1 accepted solution
  • 8066 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!