- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-02-2021 06:49 AM
Hi Team,
We have a query whether we can able to block a specific device from Connecting our Global Protect VPN by using the Device MAC Address.
Please review and share us with your thoughts. Awaiting for your reply !!
Best Regards,
Sahul Hameed
03-02-2021 06:59 AM
Not via MAC address. You would do this by creating an entry within the Device Block List and specifying the Host ID and Hostname of the blocked endpoint.
03-02-2021 06:59 AM
Not via MAC address. You would do this by creating an entry within the Device Block List and specifying the Host ID and Hostname of the blocked endpoint.
03-02-2021 07:10 AM
Hi @BPry ,
Thanks for your response. How do I get the Host ID information from a Machine to configure the Device Block List.
Also one more query is that, do we need to a have any specific subscription for using Device Block List feature in PA Firewall.
Best Regards,
Sahul Hameed
03-02-2021 07:15 AM
The Host ID field is visible in the GlobalProtect logs (I don't know if this is a default field, so you may have to view detailed logs or simply select it so it's visible). You don't need a GlobalProtect subscription to have the ability to use this feature.
03-02-2021 07:41 AM
@BPry ,
Thanks for your respose. I will check on this and will share you with the outcome shortly.
Best Regards,
Sahul Hameed
03-03-2021 04:47 AM
@BPry ,
Under Global Protect Logs we are unable to get the Host-ID information for Linux based machines. So is this related to Licensing. Since we don't have a valid subscription for GP gateway. Please share your thoughts.
Best Regards,
Sahul Hameed
03-03-2021 06:22 AM
If you don't have a GlobalProtect subscription then your Linux agents are using X-Auth instead of the actual GlobalProtect agent. In that case, a Host ID isn't generated and you don't have a clear cut way to block any one particular endpoint.
03-05-2021 04:33 AM
@BPry ,
Query 1 --> Whether can we able to see the logs for the user machine which we have blocked using the Host-ID in case if they try to connect to the Global Protect?.
Query 2 --> Also in Global Protect logs, for some of the MAC and Windows machine Host-ID information is not captured by the Agent what will be the possible cause for this and how to resolve this .
Snap for Host ID not captured for some and captured for some for the same machine itself:
Please let us know if you have thoughts on this below mentioned queries. Awaiting for your response !!
Best Regards,
Sahul Hameed
03-08-2021 01:20 AM
Hi @BPry ,
Any inputs on my 2nd query because i found out the answer for the 1st query.
I am still waiting get an inputs from you for my 2nd query. Please review and share something on this. Awaiting for your response !!
Best Regards,
Sahul Hameed
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!