<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to authenticate user to GlobalProtect using OpenLDAP in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-authenticate-user-to-globalprotect-using-openldap/m-p/514328#M3148</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38551"&gt;@Jee.Khai&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you actually validated the authentication profile that you're using by running the&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;test authentication authentication-profile&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt; command and verified that this is working properly? You should also verify in the logs the actual failure reason being documented by the firewall.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2022 20:40:33 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2022-09-08T20:40:33Z</dc:date>
    <item>
      <title>Unable to authenticate user to GlobalProtect using OpenLDAP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-authenticate-user-to-globalprotect-using-openldap/m-p/514233#M3142</link>
      <description>&lt;P&gt;i've configured the LDAP profile, Authentication profile, User-ID Mapping, GP Portal and Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when i use a user from the 'mapped-group', the globalprotect gave me 'authentication failed'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advice. TQ&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 07:34:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-authenticate-user-to-globalprotect-using-openldap/m-p/514233#M3142</guid>
      <dc:creator>Jee.Khai</dc:creator>
      <dc:date>2022-09-08T07:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to authenticate user to GlobalProtect using OpenLDAP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-authenticate-user-to-globalprotect-using-openldap/m-p/514328#M3148</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/38551"&gt;@Jee.Khai&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you actually validated the authentication profile that you're using by running the&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;test authentication authentication-profile&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt; command and verified that this is working properly? You should also verify in the logs the actual failure reason being documented by the firewall.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 20:40:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-authenticate-user-to-globalprotect-using-openldap/m-p/514328#M3148</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-09-08T20:40:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to authenticate user to GlobalProtect using OpenLDAP</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-authenticate-user-to-globalprotect-using-openldap/m-p/514386#M3152</link>
      <description>&lt;P&gt;Hi, thanks for the feedback. I've checked by running the command and there's no problem here.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JeeKhai_0-1662706349906.png" style="width: 580px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43765i174E3202E35A6CE3/image-dimensions/580x208/is-moderation-mode/true?v=v2" width="580" height="208" role="button" title="JeeKhai_0-1662706349906.png" alt="JeeKhai_0-1662706349906.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;After doing more research, it appears that the settings on Authentication Profile, Portal and Gateway do not play nice with the 'ou=people,dc=domain,dc=local' as 'source user'. GlobalProtect connection will show 'Authentication Failed' with this setting.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But when i changed this to 'all' or 'any' on Authentication Profile, Portal and Gateway, GlobalProtect connection using the user 'dpot' works without any issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please refer to the following screen shots;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="User Mapping" style="width: 598px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43762i21159C0CF0B1BB0F/image-dimensions/598x189/is-moderation-mode/true?v=v2" width="598" height="189" role="button" title="user.mapping.PNG" alt="User Mapping" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;User Mapping&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Authentication Profile" style="width: 595px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43763i36CA79534D6C7ADC/image-dimensions/595x210/is-moderation-mode/true?v=v2" width="595" height="210" role="button" title="authentication.profile.PNG" alt="Authentication Profile" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Authentication Profile&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Gateway  Setting" style="width: 604px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43761i1FBEFCED80739073/image-dimensions/604x139/is-moderation-mode/true?v=v2" width="604" height="139" role="button" title="gateway.PNG" alt="Gateway  Setting" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Gateway  Setting&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Portal Setting" style="width: 605px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43764iC09050B982A3518D/image-dimensions/605x158/is-moderation-mode/true?v=v2" width="605" height="158" role="button" title="portal.PNG" alt="Portal Setting" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Portal Setting&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Perhaps you have any idea why?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 06:57:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-authenticate-user-to-globalprotect-using-openldap/m-p/514386#M3152</guid>
      <dc:creator>Jee.Khai</dc:creator>
      <dc:date>2022-09-09T06:57:52Z</dc:date>
    </item>
  </channel>
</rss>

