Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Is panorama able to see only the devices in their country with RO access.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Is panorama able to see only the devices in their country with RO access.

L2 Linker

Hello Community,

 

Customer has 2 Panorama devices in A/P. They have devices on boarded to panorama. The requirement is the specific country will be able to see only the devices in their country with RO access.

The Authentication method will be SAML with SSO.

Could you please suggest how this could be fulfilled and how many Metadata files and certificates will be required ?

Do they need multiple SAML Identity provider and authentication profile configured ?

Do they need to assign admin role and access-domain to each authentication profile ?

Do they need to add them in sequence in the Panorama--> Management---> Authentication ?

 

They checked following guide :

Identity Provider Configuration for SAML
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008UXP
Configure SAML Authentication for Panorama Administrators
https://docs.paloaltonetworks.com/panorama/10-0/panorama-admin/set-up-panorama/set-up-administrative...

 

Customer has to provide individual country access to their specific set of firewalls. So they have to create multiple access domain for them.

If they go by the document then they have to create multiple authentication profile and add access domain to that.

In panorama management setting they can only add a single authentication profile.

Also if they add multiple authentication profile per country how many SAML IDP profile they have to create?

How many SAML metadata file we need?

How to attach multiple authentication profile to panorama management setting?

Authentication sequence does not work properly here as per their past experience.

 

Really i m not sure if country-based access control to Panorama is possible.

I think that Panorama cannot filter it but i don't know if we could with the SAML idp.

 

Many thanks in advance for your reply.

 

Best regards

 

0 REPLIES 0
  • 1376 Views
  • 0 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!