r/networking 14d ago

Design Global Protect

[deleted]

9 Upvotes

21 comments sorted by

View all comments

7

u/mattmann72 14d ago

You can't technically block them from connecting, but with HIP checks you can prevent them from accessing anything.

With some MFA conditional access policies you can prevent authentication from Linux or MacOS.

9

u/RagingNoper 14d ago

You can actually restrict portal/gateway access based on OS in the portal client auth section.

1

u/JJaska 13d ago

Though you can easily configure a Linux connecting to just tell GP portal that its a windows. Also capturing HIP reports and forging them is possible... But this narrows down the users willing to do this into a very small minority, but if they already are Linux-users...