Wednesday, March 22, 2017

Palo Alto Networks - Clientless VPN and RDP

With the 8.0 release of the PAN-OS operating system, the ability to access applications via web portal has now been added. This is sometimes referred to as "Clientless VPN." Prior to this release, some existing Palo Alto Networks customers may have been hesitant to fully migrate away from point products like PulseSecure or Aventail because they offer pretty robust capabilities around Clientless VPN. Although this capability is still relatively new to the platform and additional features will be added over time, I thought I would highlight how one can currently leverage Clientless VPN for remote access to a desktop.

In its current state, the Palo Alto Networks client-less VPN supports access to internal applications via web browser. With the development of HTML5, this means that we can leverage tools like Apache Guacamole. In this scenario, we are going to leverage this application.
  • Chase Wright has a fully scripted version of the Apache Guacamole install for Ubuntu here. Just in case his site is not accessible for some reason, here are some of the details (I would recommend viewing all details/comments on his site):
    • The following will install Guacamole 0.9.11, Tomcat 8, and MySQL for you. All you have to do is pick a MySQL Root Password and change the guacamole_user password
    wget https://raw.githubusercontent.com/MysticRyuujin/guac-install/master/guac-install.sh
    chmod +x guac-install.sh
    apt-get update
    apt-get -y install dos2unix
    dos2unix guac-install.sh
    ./guac-install.sh
    • You will be prompted to enter passwords for mysql.
    • Reboot once the install is complete.
    • Once rebooted, navigate to the GUI (http://<IP address of Ubuntu machine>:8080/guacamole)
      • user: guacadmin
      • password: guacadmin
    • Within the GUI, you can add multiple multiple users, as well as add connection types, like RDP.
  • Within the firewall, we will build upon my first GlobalProtect post, by adding Clientless VPN functionality.
    • Navigate to Network -> GlobalProtect -> Clientless Apps -> Add
      • Enter a Name for the Clientless Application
      • Enter the Application Home URL
        • This is the URL of the Apache Guacamole server
      • Click OK
    • Navigate to Network -> GlobalProtect -> Portals -> (Select the portal) -> Clientless VPN -> General
      • Enable the Clientless VPN
      • Enter a Hostname
        • This should be the FQDN or IP address of the GlobalProtect Portal
      • Select a Security Zone
        • To keep things simple in this example, I have selected the zone in which the Clientless Application resides
      • Select a DNS Proxy
        • For more information on how to configure DNS Proxy, see this post
    • Navigate to the Applications tab and select Add.
      • Enter a Name
      • Select the Application that was previously created
      • Click OK
    • Click OK
    • Commit the configuration
  • You can now test remote access to the application via Clientless VPN by navigating to the FQDN/IP of the GlobalProtetct Portal (https://<FQDN or IP>/)
  • Once logged in, there will be an option to select the application
  • Upon selecting the application, you will be redirected to the Apache Guacamole login page, and upon logging in, you will have successfully established an RDP session through your web browser



7 comments:

  1. VPN protects all your information by preventing any third parties to see your location or traffic's nature. When you are connected with a USA VPN IP, it keeps the ISPs from performing any deep packet inspection or inspecting your traffic's nature. John

    ReplyDelete
  2. All of them have plans to have networks of their own in this era of internet boom. Intranets have been around for a while now and they are available for use by the employees of a particular company. why use VPN

    ReplyDelete
  3. If you want to buy vpn service, you will get 30 days free trial, you can get discount only after using Promo Codes which offer discount up to 20%.

    ReplyDelete
  4. i have recently purchased VPN Premium service and used Promo Codes that give me 20% discount, If you want to buy VPN premium service you can visit this website and get Coupon Codes to get discount.

    ReplyDelete
  5. VPN client is a better VPN than all of VPN on internet, If you want to buy Premium VPN you should use VPN promo Codes which give 20% Discount.

    ReplyDelete


  6. flipkart big shopping days,
    flipkart big shopping days sale,
    flipkart big shopping days 2018,
    flipkart big shopping days offers,
    flipkart big shopping days sale 2018,
    flipkart next big shopping days,
    big shopping days in flipkart,
    flipkart online shopping big billion day,
    flipkart big apple shopping day,
    flipkart big shopping days 2017,
    flipkart big shopping days terms and conditions,
    flipkart big shopping days sbi offer,
    flipkart big shopping days hdfc offer,
    flipkart big shopping days mobiles,
    flipkart big shopping days 2018 redmi note 5 pro,
    flipkart big shopping days 2018 offers,
    flipkart big shopping days date,
    flipkart big shopping days hdfc,
    flipkart big shopping days oppo f7,
    flipkart big billion day online shopping,
    big app shopping days in flipkart,
    flipkart big shopping days 2016,
    flipkart big shopping days 2017 sbi offer,
    flipkart big shopping days july 2018,
    flipkart big shopping days may,
    flipkart big shopping days may 2018




    flipkart emi for debit card,
    flipkart debit card emi,
    flipkart emi debit card sbi,
    flipkart sbi debit card emi,
    flipkart icici debit card emi,
    flipkart emi debit card mobile,
    flipkart debit card offers,
    flipkart offer debit card,
    flipkart debit card emi icici,
    flipkart sbi debit card offer,
    flipkart hdfc debit card emi
    flipkart emi on debit card sbi,
    flipkart axis debit card emi,
    flipkart hdfc debit card offer,
    flipkart icici debit card offer,
    flipkart emi debit card icici,
    flipkart emi debit card axis bank,
    flipkart sbi debit card emi offer,
    flipkart sbi debit card emi eligibility check,
    flipkart refund to debit card,
    flipkart debit card emi purchase,
    flipkart debit card emi message,
    flipkart debit card emi products list,
    flipkart axis bank debit card emi,
    flipkart debit card emi terms and conditions,
    flipkart debit card emi bob,
    flipkart debit card emi news,
    flipkart debit card emi iob,
    flipkart emi without debit card,
    flipkart debit card loan,
    flipkart debit card emi ,
    flipkart pe debit card emi kaise banaye,
    flipkart hdfc debit card emi products,
    flipkart debit card no cost emi,
    flipkart accept debit card for emi,
    flipkart debit card emi banks,
    flipkart debit card emi option hdfc,
    flipkart hdfc debit card emi offer,
    flipkart debit card emi video,
    flipkart par debit card se emi,
    flipkart debit card emi hdfc sms,
    flipkart debit card emi kaise kare,
    flipkart hdfc bank debit card emi,
    flipkart emi on debit card quora,
    flipkart debit card emi union bank,
    flipkart debit card emi tamil,
    flipkart debit card emi in hindi,
    flipkart debit card emi bank of baroda,
    flipkart debit card emi indian bank,
    flipkart debit card emi sbi in hindi,
    flipkart debit card emi hindi,
    flipkart debit card emi yes bank,
    flipkart sbi debit card emi eligibility check sms,
    flipkart debit card payment,
    flipkart debit card payment offers,
    flipkart debit card emi not eligible,
    flipkart debit card emi number,
    flipkart debit card emi youtube,
    flipkart icici bank debit card emi,
    flipkart hdfc debit card emi eligibility,
    flipkart debit card emi rules,
    flipkart debit card emi 2018,
    flipkart debit card emi indusind bank,
    flipkart axis debit card offer,
    flipkart axis bank debit card offer,
    flipkart debit card ad,
    flipkart pnb debit card offer,
    flipkart debit card emi quora,
    flipkart axis bank debit card

    ReplyDelete
  7. A great website with a lot of good information about science and technology. Thank you for creating this website.

    FNF Play Game download

    Friday Night Funkin Mods download

    ReplyDelete