<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GlobalProtect Multiple Auth Failed in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-auth-failed/m-p/548606#M4192</link>
    <description>&lt;P&gt;My GP is only using local database authentication.&lt;/P&gt;
&lt;P&gt;My goal was for a small group to have access to specific resources and the everyone else to have access to much narrower resources.&lt;/P&gt;
&lt;P&gt;I created 2 Authentication Profiles:&amp;nbsp; 1 with the limited members and the other with everyone else.&amp;nbsp; The one with limited members I created a local User Group and used that in the Auth profile.&amp;nbsp; The other Auth Profile I just added all the other local users directly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I tried was in both the Portal and Gateway was to create 2 Auths under Portal&amp;gt; Agent and under Gateway &amp;gt; Agent &amp;gt; Client settings.&amp;nbsp; I set the order so the limited group Auth came first specifying the local User Group and then a 2nd Auth with the Users set to any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Per the logs, the Portal authenticated just fine.&amp;nbsp; The issue was at the Gateway where authentication was failing.&lt;/P&gt;
&lt;P&gt;Under Monitor &amp;gt; Global Protect the log was showing gateway authentication was failing with "Authentication failed:&amp;nbsp; invalid username or password".&amp;nbsp; We did verify that the correct username and password was being used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In an effort to get things working I ended up creating and Authentication sequence, removed the second Auth from both the Portal and the Gateway and then it all started working correctly.&amp;nbsp; It's just not what I wanted.&amp;nbsp; I had to "fix" it by using Security Policies to limit who had access to what.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the documentation and forums and couldn't find anything on my situation.&amp;nbsp; AFAIK I was setting this up and using it as intended.&amp;nbsp; Again, Portal auth worked fine but it failed at the Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone can shed some light?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2023 18:02:19 GMT</pubDate>
    <dc:creator>CafNetMatt</dc:creator>
    <dc:date>2023-07-07T18:02:19Z</dc:date>
    <item>
      <title>GlobalProtect Multiple Auth Failed</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-auth-failed/m-p/548606#M4192</link>
      <description>&lt;P&gt;My GP is only using local database authentication.&lt;/P&gt;
&lt;P&gt;My goal was for a small group to have access to specific resources and the everyone else to have access to much narrower resources.&lt;/P&gt;
&lt;P&gt;I created 2 Authentication Profiles:&amp;nbsp; 1 with the limited members and the other with everyone else.&amp;nbsp; The one with limited members I created a local User Group and used that in the Auth profile.&amp;nbsp; The other Auth Profile I just added all the other local users directly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I tried was in both the Portal and Gateway was to create 2 Auths under Portal&amp;gt; Agent and under Gateway &amp;gt; Agent &amp;gt; Client settings.&amp;nbsp; I set the order so the limited group Auth came first specifying the local User Group and then a 2nd Auth with the Users set to any.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Per the logs, the Portal authenticated just fine.&amp;nbsp; The issue was at the Gateway where authentication was failing.&lt;/P&gt;
&lt;P&gt;Under Monitor &amp;gt; Global Protect the log was showing gateway authentication was failing with "Authentication failed:&amp;nbsp; invalid username or password".&amp;nbsp; We did verify that the correct username and password was being used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In an effort to get things working I ended up creating and Authentication sequence, removed the second Auth from both the Portal and the Gateway and then it all started working correctly.&amp;nbsp; It's just not what I wanted.&amp;nbsp; I had to "fix" it by using Security Policies to limit who had access to what.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked the documentation and forums and couldn't find anything on my situation.&amp;nbsp; AFAIK I was setting this up and using it as intended.&amp;nbsp; Again, Portal auth worked fine but it failed at the Gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone can shed some light?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 18:02:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/globalprotect-multiple-auth-failed/m-p/548606#M4192</guid>
      <dc:creator>CafNetMatt</dc:creator>
      <dc:date>2023-07-07T18:02:19Z</dc:date>
    </item>
  </channel>
</rss>

