<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating 2 different LDAP servers in Palo Alto for Global Protect VPN authentication. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443192#M2046</link>
    <description>&lt;P&gt;Hi Abdul,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the update. Just want to check, if there is any other alternate solution apart from the above, as there is trust between both domain. Is it possible to integrate Palo Alto with on LDAP server &amp;amp; users in other domain also can use the domain trust to get connected via Global Protect VPN.&lt;/P&gt;</description>
    <pubDate>Mon, 25 Oct 2021 12:51:39 GMT</pubDate>
    <dc:creator>preetpk</dc:creator>
    <dc:date>2021-10-25T12:51:39Z</dc:date>
    <item>
      <title>Integrating 2 different LDAP servers in Palo Alto for Global Protect VPN authentication.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443180#M2044</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a requirement as users belonging to 2 different domains (for eg: local.ae &amp;amp; local.co.ae) need to connect via Palo Alto global protect VPN. Is it possible to integrate Palo Alto with 2 different LDAP profile, so that both local.ae &amp;amp; local.co.ae domain users can connect remotely over Global Protect VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 11:57:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443180#M2044</guid>
      <dc:creator>preetpk</dc:creator>
      <dc:date>2021-10-25T11:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating 2 different LDAP servers in Palo Alto for Global Protect VPN authentication.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443187#M2045</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71795"&gt;@preetpk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you can use both profiles in an Authentication Sequence profile, then use this Sequence profile for&amp;nbsp; GP authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 12:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443187#M2045</guid>
      <dc:creator>Abdul-Fattah</dc:creator>
      <dc:date>2021-10-25T12:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating 2 different LDAP servers in Palo Alto for Global Protect VPN authentication.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443192#M2046</link>
      <description>&lt;P&gt;Hi Abdul,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the update. Just want to check, if there is any other alternate solution apart from the above, as there is trust between both domain. Is it possible to integrate Palo Alto with on LDAP server &amp;amp; users in other domain also can use the domain trust to get connected via Global Protect VPN.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 12:51:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443192#M2046</guid>
      <dc:creator>preetpk</dc:creator>
      <dc:date>2021-10-25T12:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating 2 different LDAP servers in Palo Alto for Global Protect VPN authentication.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443241#M2047</link>
      <description>&lt;P&gt;You need to create two separate LDAP Server Profiles (one for each server).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you need to create two separate Authentication Profiles (one for each LDAP server).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you need to create an Authentication Sequence that lists which order you want to query the LDAP servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then you configure your GlobalProtect setup to use the Authentication Sequence to authenticate clients.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That way, when a client connects to GlobalProtect and puts in their username and password, GlobalProtect will check the LDAP servers in the Authentication Sequence.&amp;nbsp; If there's a working authentication from the first LDAP server, then the client is connected; if not, the second LDAP server is checked.&amp;nbsp; If there's a working authentication from that one, then the client is connected; if not, the connection fails.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You have to treat the LDAP servers as separate entities.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Oct 2021 17:49:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/integrating-2-different-ldap-servers-in-palo-alto-for-global/m-p/443241#M2047</guid>
      <dc:creator>fjwcash</dc:creator>
      <dc:date>2021-10-25T17:49:27Z</dc:date>
    </item>
  </channel>
</rss>

