<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to permit GP access with two different domains? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/446047#M2114</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169083"&gt;@Amaro123&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Did you update your authentication profile to actually include the new LDAP server profile? It doesn't look like you did, so that new LDAP server profile isn't actually being used. The initial auth-fail message you have in your picture is what you need to correct before going any further.&lt;/P&gt;</description>
    <pubDate>Sun, 07 Nov 2021 15:06:35 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-11-07T15:06:35Z</dc:date>
    <item>
      <title>How to permit GP access with two different domains?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/445558#M2104</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm setting up a second authentication domain in GP but I'm not successful trying to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The domain DC=domain1,DC=br,DC=local works normally.&lt;/P&gt;&lt;P&gt;The new domain DC=domain999,DC=local does not work. When I try to authenticate through it I see in the logs that it failed but it recognized the domain and the IP of the AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This new domain I configured in: Device&amp;gt;Server Profiles&amp;gt;LDAP.&lt;/P&gt;&lt;P&gt;Then on: Device&amp;gt;Server Profiles&amp;gt;User Identification&amp;gt;Group Mapping Settings&lt;/P&gt;&lt;P&gt;Then on:Network&amp;gt;GP&amp;gt;Portals&amp;gt;"vpn_portal"&amp;gt;Agent&amp;gt;^vpn_agent"&amp;gt;User/User Group&lt;/P&gt;&lt;P&gt;Then on:Network&amp;gt;GP&amp;gt;Gateways&amp;gt;"vpn_gtw"&amp;gt;Agent&amp;gt;Client Settings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I insert domain999.local/user.name, my authentication failure and generate these logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Amaro123_0-1636057013502.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37509iC625B3E53776C6FB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Amaro123_0-1636057013502.png" alt="Amaro123_0-1636057013502.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 20:13:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/445558#M2104</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-11-04T20:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to permit GP access with two different domains?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/446047#M2114</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169083"&gt;@Amaro123&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Did you update your authentication profile to actually include the new LDAP server profile? It doesn't look like you did, so that new LDAP server profile isn't actually being used. The initial auth-fail message you have in your picture is what you need to correct before going any further.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Nov 2021 15:06:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/446047#M2114</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-07T15:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to permit GP access with two different domains?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/446304#M2123</link>
      <description>&lt;P&gt;Hi BPry,&lt;BR /&gt;&lt;BR /&gt;My Authentication Profile before this configuration had local&lt;BR /&gt;authentication and an LDAP. Now, in addition to this same configuration, it&lt;BR /&gt;also has the new LDAP.&lt;BR /&gt;&lt;BR /&gt;In the image I showed he is trying to authenticate to the new LDAP.&lt;BR /&gt;&lt;BR /&gt;When I test this same user via CLI, my authentication is successful.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="unnamed.png" style="width: 944px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37548iCBF98B33F9473323/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="unnamed.png" alt="unnamed.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 21:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/446304#M2123</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-11-08T21:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to permit GP access with two different domains?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/446554#M2125</link>
      <description>&lt;P&gt;Are you using the username modifier in the auth profile... i only ask as I’m sure this is ignored when using cli.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would use Monitor/Packet Capture with the ldap server in a filter to see what the palo is sending. It may be adding additional information to the request...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2021 18:37:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/how-to-permit-gp-access-with-two-different-domains/m-p/446554#M2125</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-11-09T18:37:40Z</dc:date>
    </item>
  </channel>
</rss>

