Symantec Access Management

 View Only
  • 1.  Advance Auth - Restict IP allowed for Enrollnment

    Posted Aug 05, 2020 06:40 AM

    Hello,
    Is it possible in some way to tighten the IPs that can do the enrollment?
    Let me explain:
    I wish that only those who have already done the enrollment can enter from outside the intranet.

    Alternatively, is it possible to make a profile without issuance ?

    Thanks in advance
    Marco



  • 2.  RE: Advance Auth - Restict IP allowed for Enrollnment

    Broadcom Employee
    Posted Aug 06, 2020 08:55 AM
    Hi Marco,

    If all those IP's are coming from same subnet you may be able to restrict them from network perspective so only those have access to the Application for enrollment, Product does not provide this capability OOTB so this is something you may need to explore at the network level.


  • 3.  RE: Advance Auth - Restict IP allowed for Enrollnment

    Posted Aug 28, 2020 08:42 AM
    Hi,
    I solved it modifing  /arcotafm/core/include.jsp checking request for "IP address" and presence of "aotpprovisioningsteps.jsp" or "migrationmessage.jsp"

    It work! 



  • 4.  RE: Advance Auth - Restict IP allowed for Enrollnment

    Posted Aug 31, 2020 05:00 AM
    Hi Marco,

    I implemented a similar feature using riskMinder. It allows to create rules OOTB, able to discriminate if a user is coming from internal or external network.
    This approach does not require you to change the AFP pages...even if I guess you found a valid solution.

    regards
    Franco