<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Connectivity Issue in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1246018#M7224</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is how it was configured before , just the domain&amp;nbsp; ( &lt;STRONG&gt;connect.org&lt;/STRONG&gt;) .&amp;nbsp; I&amp;nbsp; get a prompt form the Duo SAML authentication and can confirm I belong to the LDAP group (&lt;STRONG&gt; connect\vpnusers&lt;/STRONG&gt; ) configured as source user in agent Config Selection Criteria , I am still getting the same error&amp;nbsp; for some reason . Somehow&amp;nbsp; the username attribute sent by Duo still do not seem to reconcile with the LDAP attribute .&lt;/P&gt;
&lt;P&gt;This is how I configured the Group Mapping User and Group Attributes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HThiam_0-1768921071672.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70403i4FC95C44DE1B8C81/image-size/medium?v=v2&amp;amp;px=400" role="button" title="HThiam_0-1768921071672.png" alt="HThiam_0-1768921071672.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jan 2026 14:59:12 GMT</pubDate>
    <dc:creator>H.Thiam</dc:creator>
    <dc:date>2026-01-20T14:59:12Z</dc:date>
    <item>
      <title>Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245683#M7214</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="167" data-end="330"&gt;I am deploying GlobalProtect and have configured the Gateway Agent Client Settings with the following Source User in the Config Selection Criteria:&amp;nbsp;&lt;STRONG style="font-family: inherit;"&gt;&lt;CODE class="whitespace-pre!"&gt;connect\vpnusers&lt;/CODE&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="358" data-end="530"&gt;I am a member of this group. The group is retrieved from our internal LDAP server via User Identification → Group Mapping, with the following attributes configured:&lt;/P&gt;
&lt;UL data-start="532" data-end="594"&gt;
&lt;LI data-start="532" data-end="574"&gt;
&lt;P data-start="534" data-end="574"&gt;&lt;STRONG data-start="534" data-end="555"&gt;Primary Username:&lt;/STRONG&gt; &lt;CODE data-start="556" data-end="572"&gt;sAMAccountName&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="575" data-end="594"&gt;
&lt;P data-start="577" data-end="594"&gt;&lt;STRONG data-start="577" data-end="587"&gt;Email:&lt;/STRONG&gt; &lt;CODE data-start="588" data-end="594"&gt;mail&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="596" data-end="800"&gt;Users authenticate to the GlobalProtect portal and gateway using SAML (Duo). The Authentication Profile that references the SAML server profile is configured with the following Username Attribute:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;SPAN&gt;&lt;SPAN class="hljs-attribute"&gt;duo_username&lt;/SPAN&gt;
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-start="824" data-end="926"&gt;The issue I am encountering is that whenever I attempt to connect, GlobalProtect fails with the error:&amp;nbsp;&lt;SPAN&gt;Matching &lt;/SPAN&gt;&lt;SPAN class="hljs-built_in"&gt;Client&lt;/SPAN&gt;&lt;SPAN&gt; Config &lt;/SPAN&gt;&lt;SPAN class="hljs-keyword"&gt;not&lt;/SPAN&gt;&lt;SPAN&gt; found&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-start="824" data-end="926"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="970" data-end="1170"&gt;However, when I change the Source User in the Config Selection Criteria to any, the connection succeeds. This indicates that the issue is specifically related to the user group–based matching.&lt;/P&gt;
&lt;P data-start="1172" data-end="1344"&gt;I strongly suspect there is a username format mismatch between SAML and LDAP. I have tried multiple variations of the username format, but none have resolved the issue.&lt;/P&gt;
&lt;P data-start="1346" data-end="1417"&gt;According to the GlobalProtect logs, the firewall is identifying me as:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre!"&gt;&lt;SPAN&gt;user1@connect.com
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P data-start="1446" data-end="1635"&gt;Can anyone please advise on how to correctly align the SAML and LDAP username formats so that the user is properly matched to the LDAP group and the correct client configuration is applied?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 21:34:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245683#M7214</guid>
      <dc:creator>H.Thiam</dc:creator>
      <dc:date>2026-01-15T21:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245684#M7215</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/826846661"&gt;@H.Thiam&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Someone with Duo can probably provide you more information, but it looks like the attribute that Duo wants to utilize would be User.Username for your authentication profile according to their &lt;A href="https://duo.com/docs/sso-paloalto-globalprotect" target="_self"&gt;docs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 21:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245684#M7215</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2026-01-15T21:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245685#M7216</link>
      <description>&lt;P&gt;Thanks for the feedback . I have tried the User.Username attribute but&amp;nbsp; same outcome . I have also come across a recommendation to update the&amp;nbsp;&lt;STRONG data-path-to-node="13,2,0" data-index-in-node="7"&gt;User Domain&lt;/STRONG&gt;&amp;nbsp; and &lt;STRONG&gt;User&amp;nbsp; Modifier&lt;/STRONG&gt; fields within the&amp;nbsp; SAML authentication profile so it forces the firewall&amp;nbsp; to match the SAML format to the LDAP group&amp;nbsp; Mapping&amp;nbsp; . However those fields are only applicable to the TACACS type .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jan 2026 22:18:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245685#M7216</guid>
      <dc:creator>H.Thiam</dc:creator>
      <dc:date>2026-01-15T22:18:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245700#M7218</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/826846661"&gt;@H.Thiam&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a similar problem with my GP SAML username format&amp;nbsp;&lt;A href="mailto:user@domain.com" target="_blank"&gt;user@domain.com&lt;/A&gt;&amp;nbsp;and my LDAP group mapping domain\user.&amp;nbsp; The users were not matching the groups.&amp;nbsp;&amp;nbsp;Changing the User Domain under Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; [edit group mapping] &amp;gt; Server Profile &amp;gt; Domain Setting caused the GP SAML usernames to change from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="mailto:user@domain.com" target="_blank" rel="nofollow noopener noreferrer"&gt;user@domain.com&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to domain\user so that the LDAP groups would work.&amp;nbsp; All other fields remained the default (except the Update Interval).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TomYoung_0-1768524467740.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70367iFF61B7042BB89716/image-size/medium?v=v2&amp;amp;px=400" role="button" title="TomYoung_0-1768524467740.png" alt="TomYoung_0-1768524467740.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jan 2026 00:48:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245700#M7218</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-01-16T00:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245930#M7222</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;. Thank you for the response . I have&amp;nbsp; replaced the User Domain value as suggested . &lt;STRONG&gt;domain\user&lt;/STRONG&gt; but getting the below error . Any ideas why ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Previously the value was only the domain without \user .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HThiam_0-1768863965598.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70399i3946B94DC9DB2CCF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="HThiam_0-1768863965598.png" alt="HThiam_0-1768863965598.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jan 2026 23:08:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245930#M7222</guid>
      <dc:creator>H.Thiam</dc:creator>
      <dc:date>2026-01-19T23:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245932#M7223</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/826846661"&gt;@H.Thiam&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You only put your domain name in the box.&amp;nbsp; Please take out the \user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 01:57:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1245932#M7223</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-01-20T01:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1246018#M7224</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is how it was configured before , just the domain&amp;nbsp; ( &lt;STRONG&gt;connect.org&lt;/STRONG&gt;) .&amp;nbsp; I&amp;nbsp; get a prompt form the Duo SAML authentication and can confirm I belong to the LDAP group (&lt;STRONG&gt; connect\vpnusers&lt;/STRONG&gt; ) configured as source user in agent Config Selection Criteria , I am still getting the same error&amp;nbsp; for some reason . Somehow&amp;nbsp; the username attribute sent by Duo still do not seem to reconcile with the LDAP attribute .&lt;/P&gt;
&lt;P&gt;This is how I configured the Group Mapping User and Group Attributes&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HThiam_0-1768921071672.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/70403i4FC95C44DE1B8C81/image-size/medium?v=v2&amp;amp;px=400" role="button" title="HThiam_0-1768921071672.png" alt="HThiam_0-1768921071672.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 14:59:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1246018#M7224</guid>
      <dc:creator>H.Thiam</dc:creator>
      <dc:date>2026-01-20T14:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1246023#M7225</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/826846661"&gt;@H.Thiam&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Domain field is the NetBIOS domain.&amp;nbsp; So, normally you would only put "connect" in the field.&amp;nbsp; Try it without the .org.&amp;nbsp; Your User and Group Attributes are correct.&amp;nbsp; So, you "&lt;SPAN&gt;can confirm I belong to the LDAP group (&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;connect\vpnusers&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;) configured as source user in agent Config Selection Criteria"?&amp;nbsp; The error you are getting says that the username does NOT match the configured user or group.&amp;nbsp;&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000PLc9" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/kcSArticleDetail?id=kA10g000000PLc9&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The username to check will be under Monitor &amp;gt; Logs &amp;gt; User-ID.&amp;nbsp; The User column should read connect\user while the User Provided by Source column should read &lt;A href="mailto:user@connect.org" target="_blank"&gt;user@connect.org&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Tom&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 16:58:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1246023#M7225</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2026-01-20T16:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Connectivity Issue</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1246132#M7228</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We only added the NetBios name and still failed however we got it working leaving the field blank . It looks like it is behaving differently with version 11.1 . But as you suggested the&amp;nbsp; domain requirement is still valid for version 10 I believe . Thanks a lot for all your feedback .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jan 2026 14:28:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-connectivity-issue/m-p/1246132#M7228</guid>
      <dc:creator>H.Thiam</dc:creator>
      <dc:date>2026-01-21T14:28:14Z</dc:date>
    </item>
  </channel>
</rss>

