Prevent users to add new portal in Gloabal Protect App

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Prevent users to add new portal in Gloabal Protect App

L1 Bithead
 

Hello Community Members, 

 

I am looking to restrict the users from adding any additional portal in the Global Protect App.

 

I know there is an option in Agent configuration that restricts users not to change the portal but that will limit users to only connecting to one portal.
We have multiple portals in our infra and we want users to give the flexibility to switch between 2-3 portals however users should not be able to add any new portals at all.
Does anyone know what configuration knob i need to configure?
3 REPLIES 3

Cyber Elite
Cyber Elite

you can set the "Enable Advanced View" to no, which will prevent them from tampering with the configuration, but allow them to switch portals

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

L1 Bithead

Thanks for your response, Looking at this KB article, it just controls the UI parameters but does not disable users to add a new portal.

Setting this flag to No, also poses another challenge that the user won't be able to collect dump or debug logs.

 

 

https://knowledgebase.paloaltonetworks.com/kCSArticleDetail?id=kA10g000000PPcc

Cyber Elite
Cyber Elite

they can't change what they can't see: the portal configuration is part of the advanced view so they wont be able to add/delete/change any of the portals

 

not sure about that article, but the disabled advanced view looks like this (no portals):

 

reaper_1-1701696689268.png

 

 

you're right they wont be able to get the log package, but you can still get the logs directly from the directory

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 593 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!