Session Notification Enforcement Profile

Use this page to configure the Session Notification Enforcement profile. You can send notification of a change in IP address to any external context server (such as a firewall Firewall is a network security system used for preventing unauthorized access to or from a private network.) by configuring that server as a generic HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands. server and adding the appropriate generic HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands. context server actions.

The content of the payload to be posted by Policy Manager to the external server is based on the REST Representational State Transfer. REST is a simple and stateless architecture that the web services use for providing interoperability between computer systems on the Internet. In a RESTful web service, requests made to the URI of a resource will elicit a response that may be in XML, HTML, JSON or some other defined format. API Application Programming Interface. Refers to a set of functions, procedures, protocols, and tools that enable users to build application software. defined by the external server.

Profile Tab

To configure a Session Notification Enforcement profile:

1. On the publisher, navigate to Configuration > Enforcement > Profiles. The Enforcement Profiles page opens.

2. Click the Add link. The Add Enforcement Profiles dialog opens.

3. From the Template drop-down, select Session Notification Enforcement.

Figure 1  Session Notification Enforcement > Profile Configuration Dialog

4. Specify the Session Notification Enforcement > Profile parameters as described in the following table:

Table 1: Session Notification Enforcement Profile Parameters

Parameter

Action/Description

Template

Select Session Notification Enforcement.

Name

Enter the name of the profile.

Description

Enter a description of the profile (recommended).

Type

The field is populated automatically with Post_Authentication.

Action

This options is disabled.

Device Group List

Select a device group from the drop-down list.

All configured device groups are listed in the Device Groups Configuration > Network > Device Groups page.

Add New Device Group

To add a new a device group, click the Add New Device Group link. See Adding and Modifying Device Groups for more information.

Attributes Tab

Figure 2  Session Notification Enforcement > Attributes Configuration Dialog

5. Specify the Session Notification Enforcement > Attributes parameters as described in the following table:

Table 2: Session Notification Enforcement > Attributes Parameters

Parameter

Action/Description

Type

Select one of the following Type attributes:

Session-Check

Session-Notify

Palo Alto integration is extended to Guest MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. Caching use cases. Configure the Session-Check attributes as follows:

Session-Check::Username = %{Endpoint:Username}

NOTE: Post authentication sends the Guest username instead of the MAC Media Access Control. A MAC address is a unique identifier assigned to network interfaces for communications on a network. address in the user ID updates.

Session-Notify: The Name options are:

Login Action

Logout Action

Server IP

Server Type

Server Type options:

Generic HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands.

Palo Alto Networks Panorama

Palo Alto Networks Firewall Firewall is a network security system used for preventing unauthorized access to or from a private network.

Server IP options: a choice of IP address/hostnames for the corresponding type of server as Value. The Target Server attribute must be specified before you can use the Server IP option.

Once the server IP address is selected, you can select Login Action or Logout Action. The list of actions defined for the selected server will be shown as available choices for Value.

This enforcement type should be used both for Palo Alto devices and any Generic HTTP Hypertext Transfer Protocol. The HTTP is an application protocol to transfer data over the web. The HTTP protocol defines how messages are formatted and transmitted, and the actions that the w servers and browsers should take in response to various commands. servers.

Name

The options displayed for the Name attribute depend on the Type attribute that was selected.

Value

The options displayed for the Value attribute depend on the Type and Name attributes that were selected.

Summary Tab

This Summary tab summarizes the parameters configured for Session Notification Enforcement.

Figure 3  Session Notification Enforcement > Summary Tab

6. Click Save.