<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: global protect ldap users have conflict session accessing private network in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/323209#M33</link>
    <description>&lt;P&gt;&lt;SPAN&gt;"You also say you're logged into&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;both machine and file sharing using domain\administrator. and then its changing source user to all network."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, exactly. as you can see on the capture as attached.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i wonder, can i solve this issue by implementing agent mode ?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2020 16:24:36 GMT</pubDate>
    <dc:creator>TowerBersamaGroup</dc:creator>
    <dc:date>2020-04-16T16:24:36Z</dc:date>
    <item>
      <title>global protect ldap users have conflict session accessing private network</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/322601#M19</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setup global protect authenticated by LDAP. Before i started, here is my running version:&lt;/P&gt;&lt;P&gt;- PA Firmware : 8.1.5&lt;/P&gt;&lt;P&gt;- GP Version &amp;nbsp;: 5.0.0&lt;/P&gt;&lt;P&gt;I found odd issue with global protect ldap authenticated user who accessing the private network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have logged in global protect with ldap authentication, let's say its "domain\user1". i want to access file sharing network and it's required domain authentication, i authenticated using "domain\administrator". Oddly, my connection is suddenly dropped. i checked on monitoring traffic log, queried by my 'source ip' and it showed that my log traffic changing from "domain\user1" to "domain\administrator" and its affected to change my initial authenticated login global protect with accessing other network. For example, previously (source user "domain\user1" global protect source-ip 172.10.1.63 destination-ip 10.10.1.100) after i authenticated my domain account to access the file server the traffic change to (source user "domain\administrator" global protect source-ip 172.10.1.63 destination-ip 10.10.1.100) it caused the connection dropped because the user is not listed or allowed in the policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kindly need help assistance to this problem, have anyone had the similar issue with global protect and ldap ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;any kind of help will be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;quay&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2020 06:19:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/322601#M19</guid>
      <dc:creator>TowerBersamaGroup</dc:creator>
      <dc:date>2020-04-14T06:19:08Z</dc:date>
    </item>
    <item>
      <title>Re: global protect ldap users have conflict session accessing private network</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/322777#M21</link>
      <description>&lt;P&gt;Hi Quay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you log onto the machine using domain\user1 and then logged into File sharing network as domain\administrator or did you log onto machine using domain\administrator account later on? Please clarify.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 00:19:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/322777#M21</guid>
      <dc:creator>vathreya</dc:creator>
      <dc:date>2020-04-15T00:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: global protect ldap users have conflict session accessing private network</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/322798#M22</link>
      <description>&lt;P&gt;Hi Vathreya,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply, i logged on to both machine and filesharing using domain\administrator. and then its changing source user to all network i accessed to.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gp-user.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25169i7865B1714BD636D4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="gp-user.jpg" alt="gp-user.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="gp-traffic.jpg" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/25170i81E75E2C1F951DB5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="gp-traffic.jpg" alt="gp-traffic.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 03:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/322798#M22</guid>
      <dc:creator>TowerBersamaGroup</dc:creator>
      <dc:date>2020-04-15T03:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: global protect ldap users have conflict session accessing private network</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/323013#M27</link>
      <description>&lt;P&gt;Hi Quay,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I still don't quite follow what you're saying:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have logged in global protect with ldap authentication, let's say its "domain\user1". i want to access file sharing network and it's required domain authentication, i authenticated using "domain\administrator". Oddly, my connection is suddenly dropped. i checked on monitoring traffic log, queried by my 'source ip' and it showed that my log traffic changing from "domain\user1" to "domain\administrator" and its affected to change my initial authenticated login global protect with accessing other network. For example, previously (source user "domain\user1" global protect source-ip 172.10.1.63 destination-ip 10.10.1.100) after i authenticated my domain account to access the file server the traffic change to (source user "domain\administrator" global protect source-ip 172.10.1.63 destination-ip 10.10.1.100) it caused the connection dropped because the user is not listed or allowed in the policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You also say you're logged into&lt;SPAN&gt;&amp;nbsp;both machine and filesharing using domain\administrator. and then its changing source user to all network.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you initially log in as domain\user 1 onto the machine, and then switched user to domain\administrator?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Varun&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 23:02:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/323013#M27</guid>
      <dc:creator>vathreya</dc:creator>
      <dc:date>2020-04-15T23:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: global protect ldap users have conflict session accessing private network</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/323209#M33</link>
      <description>&lt;P&gt;&lt;SPAN&gt;"You also say you're logged into&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;both machine and file sharing using domain\administrator. and then its changing source user to all network."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes, exactly. as you can see on the capture as attached.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i wonder, can i solve this issue by implementing agent mode ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 16:24:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-ldap-users-have-conflict-session-accessing/m-p/323209#M33</guid>
      <dc:creator>TowerBersamaGroup</dc:creator>
      <dc:date>2020-04-16T16:24:36Z</dc:date>
    </item>
  </channel>
</rss>

