<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect SAML:  authentication works fails on matching client config not found.  Group not matching. in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-authentication-works-fails-on-matching/m-p/558136#M4384</link>
    <description>&lt;P&gt;I ended up contacting Palo support and I for ones got a good engineer on the line.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We figured out the issue was with the certificate profile, without client certificate it worked.&amp;nbsp; Normally the domain is taken from the Certificate.&amp;nbsp; For the group mapping you have to specify the NEBTIOS domain name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_1-1694786828801.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53760iDC3E399328FB3FE2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_1-1694786828801.png" alt="zGomez_1-1694786828801.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This solved the group mapping issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2023 14:07:52 GMT</pubDate>
    <dc:creator>zGomez</dc:creator>
    <dc:date>2023-09-15T14:07:52Z</dc:date>
    <item>
      <title>Global Protect SAML:  authentication works fails on matching client config not found.  Group not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-authentication-works-fails-on-matching/m-p/556778#M4365</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am trying to configure globalprotect to use SAML authentication for the portal and gateway.&amp;nbsp; The authentication seems to work but when, but i am not getting a valid client config when i use groups in allow list.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sure it is related to group mapping and user id but don't know where exactly it is going wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have the following configuration on Azure:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_0-1694012059685.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53468i1EA65785F34ACB0E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_0-1694012059685.png" alt="zGomez_0-1694012059685.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_1-1694012177202.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53469i189EB89C8F542853/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_1-1694012177202.png" alt="zGomez_1-1694012177202.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;When authenticating i am seeing the following in the logs on the gateway.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_2-1694012661065.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53470iA0539894CBD015E1/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_2-1694012661065.png" alt="zGomez_2-1694012661065.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First it tries with username.firstname this fails then it tries with the formated version and the authentication works.&lt;/P&gt;
&lt;P&gt;My authentication profile is configured as follows, it also has an allow list that is allowing only certain group.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_3-1694012917716.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53471i81CB54EF72C009B6/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_3-1694012917716.png" alt="zGomez_3-1694012917716.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This seems to be working besides the fact that it tries with 2 different formats.&amp;nbsp; Then the user tries to fetch the config with the same group limitation as the authentication profile this seems to fail.&amp;nbsp; When i remove the group it works and the client can get it's config.&lt;/P&gt;
&lt;P&gt;I have double checked the format off the groupname and both are the same.&lt;/P&gt;
&lt;P&gt;My groupmapping is configured as follows.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_5-1694013360208.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53473i1A4EF51913172563/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_5-1694013360208.png" alt="zGomez_5-1694013360208.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Do i need to add alternate username 1:&amp;nbsp; userpincipalname?&lt;/P&gt;
&lt;P&gt;The problem is located somewhere over here.&amp;nbsp; I just don't understand why i works for the authentication and not for the getclient config.&lt;/P&gt;
&lt;P&gt;Any help on this would be appreciated or some clarification on the claims vs auth/group mapping.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 15:23:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-authentication-works-fails-on-matching/m-p/556778#M4365</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2023-09-06T15:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect SAML:  authentication works fails on matching client config not found.  Group not matching.</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-authentication-works-fails-on-matching/m-p/558136#M4384</link>
      <description>&lt;P&gt;I ended up contacting Palo support and I for ones got a good engineer on the line.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We figured out the issue was with the certificate profile, without client certificate it worked.&amp;nbsp; Normally the domain is taken from the Certificate.&amp;nbsp; For the group mapping you have to specify the NEBTIOS domain name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zGomez_1-1694786828801.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53760iDC3E399328FB3FE2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="zGomez_1-1694786828801.png" alt="zGomez_1-1694786828801.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This solved the group mapping issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 14:07:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-saml-authentication-works-fails-on-matching/m-p/558136#M4384</guid>
      <dc:creator>zGomez</dc:creator>
      <dc:date>2023-09-15T14:07:52Z</dc:date>
    </item>
  </channel>
</rss>

