<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to connet via Global protect and ISE - &amp;quot;Matching client config not found&amp;quot; in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-connet-via-global-protect-and-ise-quot-matching-client/m-p/1002559#M6346</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;at the moment i'm authenticating users via the local database on palo alto firewall for vpn gp users; what 'id like to do is trying to authenticate vpn users via Cisco Ise.&lt;/P&gt;
&lt;P&gt;I've configured local users on Ise and what i want to do is that when a user tries to login, ise checks if the user is present in the local group, and if present it sends a radius-accept packet back to the Palo alto firewall.&lt;/P&gt;
&lt;P&gt;On ise side everything it's working but i'm receiving the&amp;nbsp;"Matching client config not found" in the global protect:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_0-1736505371308.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65143i74323853DF951D2F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_0-1736505371308.jpeg" alt="MAerre_0-1736505371308.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the log from gp monitor:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_1-1736505393553.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65144iF9CC44E46774F836/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_1-1736505393553.jpeg" alt="MAerre_1-1736505393553.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and this is the actual rule:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_2-1736505414395.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65145i668A5C39E113A7A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_2-1736505414395.jpeg" alt="MAerre_2-1736505414395.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;what i can't understand is how to get the correct client config, because this setting is configured on the gateway tab but it's referred to only gp local database users.......&lt;/P&gt;
&lt;P&gt;Did you face this issue? Do you know how to fix?&lt;/P&gt;
&lt;P&gt;Furthermore how should the policy be configured? I can't use any filter in source ip/user because i don't know how to retrieve this data.&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jan 2025 11:25:28 GMT</pubDate>
    <dc:creator>MAerre</dc:creator>
    <dc:date>2025-01-10T11:25:28Z</dc:date>
    <item>
      <title>Unable to connet via Global protect and ISE - "Matching client config not found"</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-connet-via-global-protect-and-ise-quot-matching-client/m-p/1002559#M6346</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;at the moment i'm authenticating users via the local database on palo alto firewall for vpn gp users; what 'id like to do is trying to authenticate vpn users via Cisco Ise.&lt;/P&gt;
&lt;P&gt;I've configured local users on Ise and what i want to do is that when a user tries to login, ise checks if the user is present in the local group, and if present it sends a radius-accept packet back to the Palo alto firewall.&lt;/P&gt;
&lt;P&gt;On ise side everything it's working but i'm receiving the&amp;nbsp;"Matching client config not found" in the global protect:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_0-1736505371308.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65143i74323853DF951D2F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_0-1736505371308.jpeg" alt="MAerre_0-1736505371308.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the log from gp monitor:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_1-1736505393553.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65144iF9CC44E46774F836/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_1-1736505393553.jpeg" alt="MAerre_1-1736505393553.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and this is the actual rule:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_2-1736505414395.jpeg" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65145i668A5C39E113A7A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_2-1736505414395.jpeg" alt="MAerre_2-1736505414395.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;what i can't understand is how to get the correct client config, because this setting is configured on the gateway tab but it's referred to only gp local database users.......&lt;/P&gt;
&lt;P&gt;Did you face this issue? Do you know how to fix?&lt;/P&gt;
&lt;P&gt;Furthermore how should the policy be configured? I can't use any filter in source ip/user because i don't know how to retrieve this data.&lt;/P&gt;
&lt;P&gt;thank you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 11:25:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-connet-via-global-protect-and-ise-quot-matching-client/m-p/1002559#M6346</guid>
      <dc:creator>MAerre</dc:creator>
      <dc:date>2025-01-10T11:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connet via Global protect and ISE - "Matching client config not found"</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-connet-via-global-protect-and-ise-quot-matching-client/m-p/1085479#M6356</link>
      <description>&lt;P&gt;which parameters did you set in the AGENT tabs (both portal and gateway), you can set restrictions (like group membership and OS etc)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="reaper_0-1736932852604.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65208i9986802972519A49/image-size/large?v=v2&amp;amp;px=999" role="button" title="reaper_0-1736932852604.png" alt="reaper_0-1736932852604.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you set all client configs to require group membership and there is a mismatch with the userid (while speaking to ISE) and the group mapping, you won't be able to fetch a client config&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you add a 'catchall' config (any/any/any) at the bottom of your agent config, you should be able to connect and continue troubleshooting from there&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 09:22:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-connet-via-global-protect-and-ise-quot-matching-client/m-p/1085479#M6356</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-01-15T09:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to connet via Global protect and ISE - "Matching client config not found"</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-connet-via-global-protect-and-ise-quot-matching-client/m-p/1085517#M6359</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;thank you for the advice.&lt;/P&gt;
&lt;P&gt;This is my client setting, i use an "any" for the 1st profile and "windows + mac" for the 2nd and 3rd; for each profile i use a different ip pool and each profile has its own group that is actually populated with all the local users.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_0-1736937389284.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65209i115EE86B0AC25D19/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_0-1736937389284.png" alt="MAerre_0-1736937389284.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;This screen is about the ACLs, at the moment i'm using the user groups to differentiate each ACL in other that users in "GROUP1" can access only their specific network and users in "GROUP2" can access other networks.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_1-1736937397582.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65210i6F785C9E05088AEC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_1-1736937397582.png" alt="MAerre_1-1736937397582.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Now using this configuration it's working, but implementing ISE no, because i'm unable to pass the correct group.&lt;/P&gt;
&lt;P&gt;The name of the local groups in ISE are different from the ones used on the Palo alto.&lt;/P&gt;
&lt;P&gt;To test, I've created the following an "any any" profile on GP gateway, and with this configuration using the local user in ISE it's working BUT i'm unable to use the different ACL anymore; thus basically allowing any user (and so all the different external consultant companies) to reach the same networks.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MAerre_2-1736938482733.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/65211iF1FF02D1A026EFCB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="MAerre_2-1736938482733.png" alt="MAerre_2-1736938482733.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Instead, what i want to achieve is to authenticate via ISE (using the local users configured on its local groups) and still continue to use the group a user belongs to to use the different ACLs to allow an external consultant to access only the networks he need to access to.&lt;BR /&gt;To answer your question: i'm not using USERID on this Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for the advice you'll give me!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2025 11:03:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/unable-to-connet-via-global-protect-and-ise-quot-matching-client/m-p/1085517#M6359</guid>
      <dc:creator>MAerre</dc:creator>
      <dc:date>2025-01-15T11:03:55Z</dc:date>
    </item>
  </channel>
</rss>

