- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-10-2022 06:03 AM
Hello,
I have Global Protect setup and people are able to connect via a VPN connection with Split Tunnel turned on.
I have a request to setup another config for a certain group in AD that would give this group of users a different IP and have Split Tunneling turned off forcing all traffic over the VPN.
I have this setup and working. If I put myself in the client settings in the config I get the correct IP and all my traffic goes over the VPN connection but if I place the group in the list it does not get applied to the user in the group.
My question is it possible to add groups to this or does it have to be the individual user.
Thank you,
Tom
06-11-2022 04:03 AM
Hello,
You can add groups, but you need to make sure the group has been pulled via your group-mapping config, and that the user is in that group in the right format.
Verify with the following commands that:
- The group is pulled by group-mapping
- The user is listed as being in that group on the firewall
- The username format format in the IP mapping matches the format of the use listed in that group, or matches an attribute for that user
> show user group-mapping state all
> show user group name <group name>
> show user ip-user-mapping ip <gp IP while connected>
> show user user-attributes user <username>
It's possible that there's a domain mismatch which often happens. Make sure that you have a domain map as well:
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFn
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!