<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't connect user group is fine but Agent Policy does not match in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-connect-user-group-is-fine-but-agent-policy-does-not-match/m-p/568420#M4705</link>
    <description>&lt;P&gt;Indeed Reaper, I've solved this with the following steps, thanks!&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Auth Profile: on domain name I've configured Netbios domain name (&lt;A href="https://community.lansweeper.com/t5/scanning-your-network/finding-your-domains-dns-and-netbios-names/ta-p/64266" target="_blank"&gt;https://community.lansweeper.com/t5/scanning-your-network/finding-your-domains-dns-and-netbios-names/ta-p/64266)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;User identification =&amp;gt; Group mapping settings =&amp;gt; I've deleted the domain that I defined there, I left the option blank. (&lt;A href="https://www.reddit.com/r/paloaltonetworks/comments/8fgvez/failed_access_via_globalprotect/" target="_blank"&gt;https://www.reddit.com/r/paloaltonetworks/comments/8fgvez/failed_access_via_globalprotect/&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I don't understand why it works but it does. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 13:26:35 GMT</pubDate>
    <dc:creator>luishoracio.arizaga</dc:creator>
    <dc:date>2023-12-05T13:26:35Z</dc:date>
    <item>
      <title>Can't connect user group is fine but Agent Policy does not match</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-connect-user-group-is-fine-but-agent-policy-does-not-match/m-p/568400#M4703</link>
      <description>&lt;P&gt;Hello, I'm running out of ideas to tshoot a GP connection problem. I have a user that is in an AD group uservpn (checked on the cli and it's fine). Added this group to Portal and GW configuration and I can't connect. If I live any for the config under user/user group for portal and Gateway it works. I see the user has this group on the CLI but somehow the firewall can't make the association on the login&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{"level":"info","time":"2023-12-05T12:25:17.046726663+01:00","message":"loadGlobalRegionFile: global region file not changed, skip building the trie"}
{"level":"info","time":"2023-12-05T12:25:52.806664649+01:00","message":"ConfigPhase2: received config phase2"}
{"level":"info","time":"2023-12-05T12:25:52.806820918+01:00","message":"ConfigPhase2: phase2 done, switched to new config ts:1701775516, version:94 (MaxTaskCount:1000 MaxAuthReqCount:4096)"}
{"level":"error","task":"439-5","time":"2023-12-05T12:27:16.5756033+01:00","message":"GetPortalClientConfig: portal CHLC_Portal was found, but no client config for req &amp;amp;{X.X.X.X luis.arizaga  Windows 1ZP5FK3  false   false  false false}"}
{"level":"error","task":"439-5","time":"2023-12-05T12:27:16.57613947+01:00","message":"authLoop write: failed to send data to unixgram:@/tmp/authd.sock, error: write unixgram @/tmp/authd_client_GP_socket_1701775066.sock-&amp;gt;@/tmp/authd.sock: write: connection refused"}
{"level":"error","time":"2023-12-05T12:27:16.576966802+01:00","message":"authLoop read: failed to receive data from auth, error: read unixgram @/tmp/authd_client_GP_socket_1701775066.sock-&amp;gt;@/tmp/authd.sock: use of closed network connection"}
{"level":"error","time":"2023-12-05T12:27:17.577205202+01:00","message":"authLoop: connection to authd is broken, reconnecting"}
{"level":"info","time":"2023-12-05T12:27:17.577584189+01:00","message":"authLoop: connection to authd is established"}
{"level":"error","task":"439-5","time":"2023-12-05T12:27:17.628630724+01:00","message":"GetPortalClientConfig: portal CHLC_Portal was found, but no client config for req &amp;amp;{X.X.X.X luis.arizaga  Windows 1ZP5FK3  false   false  false false}"}
{"level":"error","task":"439-5","time":"2023-12-05T12:27:17.629557248+01:00","message":"gpGetconfig: Failed to get portal config"}
&lt;/LI-CODE&gt;
&lt;P&gt;Does anyone have a suggestion about how to tshoot this?&lt;/P&gt;
&lt;P&gt;Thanks for your time.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Luis&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 11:35:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-connect-user-group-is-fine-but-agent-policy-does-not-match/m-p/568400#M4703</guid>
      <dc:creator>luishoracio.arizaga</dc:creator>
      <dc:date>2023-12-05T11:35:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect user group is fine but Agent Policy does not match</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-connect-user-group-is-fine-but-agent-policy-does-not-match/m-p/568415#M4704</link>
      <description>&lt;P&gt;does the username contained inside the group (show user group name &amp;lt;yourgrouphere&amp;gt;) match EXACTLY with the username the authentication profile is receiving?&lt;/P&gt;
&lt;P&gt;of group mapping has you as domain\user and your auth profile receives &lt;A href="mailto:user@domain" target="_blank"&gt;user@domain&lt;/A&gt;&amp;nbsp;, that is not a match&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can fix that by changing the username modifier in the authentication profile, or changing the group mapping user attribute&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 13:08:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-connect-user-group-is-fine-but-agent-policy-does-not-match/m-p/568415#M4704</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2023-12-05T13:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect user group is fine but Agent Policy does not match</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-connect-user-group-is-fine-but-agent-policy-does-not-match/m-p/568420#M4705</link>
      <description>&lt;P&gt;Indeed Reaper, I've solved this with the following steps, thanks!&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Auth Profile: on domain name I've configured Netbios domain name (&lt;A href="https://community.lansweeper.com/t5/scanning-your-network/finding-your-domains-dns-and-netbios-names/ta-p/64266" target="_blank"&gt;https://community.lansweeper.com/t5/scanning-your-network/finding-your-domains-dns-and-netbios-names/ta-p/64266)&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;User identification =&amp;gt; Group mapping settings =&amp;gt; I've deleted the domain that I defined there, I left the option blank. (&lt;A href="https://www.reddit.com/r/paloaltonetworks/comments/8fgvez/failed_access_via_globalprotect/" target="_blank"&gt;https://www.reddit.com/r/paloaltonetworks/comments/8fgvez/failed_access_via_globalprotect/&lt;/A&gt;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;I don't understand why it works but it does. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 13:26:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/can-t-connect-user-group-is-fine-but-agent-policy-does-not-match/m-p/568420#M4705</guid>
      <dc:creator>luishoracio.arizaga</dc:creator>
      <dc:date>2023-12-05T13:26:35Z</dc:date>
    </item>
  </channel>
</rss>

