Block a specific MAC address to be barred from connecting through our Global protect VPN

Announcements

Changes to the LIVEcommunity experience are coming soon... Here's what you need to know.

Reply
SahulH
L3 Networker

Block a specific MAC address to be barred from connecting through our Global protect VPN

Hi Team,

 

We have a query whether we can able to block a specific device from Connecting our Global Protect VPN by using the Device MAC Address.

 

Please review and share us with your thoughts. Awaiting for your reply !!

 

Best Regards,

Sahul Hameed


Accepted Solutions
BPry
Cyber Elite

@SahulH,

Not via MAC address. You would do this by creating an entry within the Device Block List and specifying the Host ID and Hostname of the blocked endpoint. 

View solution in original post


All Replies
BPry
Cyber Elite

@SahulH,

Not via MAC address. You would do this by creating an entry within the Device Block List and specifying the Host ID and Hostname of the blocked endpoint. 

View solution in original post

SahulH
L3 Networker

Hi @BPry ,

 

Thanks for your response. How do I get the Host ID information from a Machine to configure the Device Block List.

 

Also one more query is that, do we need to a have any specific subscription for using Device Block List feature in PA Firewall.

 

Best Regards,

Sahul Hameed

BPry
Cyber Elite

@SahulH,

The Host ID field is visible in the GlobalProtect logs (I don't know if this is a default field, so you may have to view detailed logs or simply select it so it's visible). You don't need a GlobalProtect subscription to have the ability to use this feature. 

SahulH
L3 Networker

@BPry ,

 

Thanks for your respose. I will check on this and will share you with the outcome shortly. 

 

Best Regards,

Sahul Hameed

SahulH
L3 Networker

@BPry ,

 

Under Global Protect Logs we are unable to get the Host-ID information for Linux based machines. So is this related to Licensing. Since we don't have a valid subscription for GP gateway. Please share your thoughts. 

 

Best Regards,

Sahul Hameed

Tags (1)
BPry
Cyber Elite

@SahulH,

If you don't have a GlobalProtect subscription then your Linux agents are using X-Auth instead of the actual GlobalProtect agent. In that case, a Host ID isn't generated and you don't have a clear cut way to block any one particular endpoint. 

SahulH
L3 Networker

@BPry ,

 

Thanks for your response !!

 

Best Regards,

Sahul Hameed

SahulH
L3 Networker

@BPry ,

 

Query 1 --> Whether can we able to see the logs for the user machine which we have blocked using the Host-ID in case if they try to connect to the Global Protect?.

 

Query 2 --> Also in Global Protect logs, for some of the MAC and Windows machine Host-ID information is not captured by the Agent what will be the possible cause for this and how to resolve this . 

 

Snap for Host ID not captured for some and captured for some for the same machine itself:

 

SahulH_0-1614947467578.png

 

Please let us know if you have thoughts on this below mentioned queries. Awaiting for your response !!

 

Best Regards,

Sahul Hameed

 

SahulH
L3 Networker

Hi @BPry ,

 

Any inputs on my 2nd query because i found out the answer for the 1st query. 

 

I am still waiting get an inputs from you for my 2nd query. Please review and share something on this. Awaiting for your response !!

 

Best Regards,

Sahul Hameed

 

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!