Groups added to VPN

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Groups added to VPN

L2 Linker

Hello,

I have Global Protect setup and people are able to connect via a VPN connection with Split Tunnel turned on.
I have a request to setup another config for a certain group in AD that would give this group of users a different IP and  have Split Tunneling turned off forcing all traffic over the VPN. 

I have this setup and working. If I put myself in the client settings in the config I get the correct IP and all my traffic goes over the VPN connection but if I place the group in the list it does not get applied to the user in the group.

My question is it possible to add groups to this or does it have to be the individual user.

Thank you,

Tom

thoffman_0-1654866175790.png

 

 

2 REPLIES 2

L3 Networker

Hello,

 

You can add groups, but you need to make sure the group has been pulled via your group-mapping config, and that the user is in that group in the right format.

Verify with the following commands that:

- The group is pulled by group-mapping

- The user is listed as being in that group on the firewall

- The username format format in the IP mapping matches the format of the use listed in that group, or matches an attribute for that user

> show user group-mapping state all
> show user group name <group name>
> show user ip-user-mapping ip <gp IP while connected>
> show user user-attributes user <username>

 

It's possible that there's a domain mismatch which often happens. Make sure that you have a domain map as well:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFn

Sr. Technical Support Engineer, Strata

Cyber Elite
Cyber Elite

@thoffman,

Does your group actually have the users listed within it, or does it consist of nested groups? If you're puling the group as @dmifsud mentioned this should work without issue as long as you aren't trying to use nested groups for this. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!