<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect not working with RADIUS NPS and LDAP on the same server. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445344#M100452</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197310"&gt;@JorgeOrtega&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, that will worked based upon the allow list.&amp;nbsp; No, you shouldn't have to type it in manually as long as you can see it under&amp;nbsp; Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; [edit group] &amp;gt; Group Include List.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Wed, 03 Nov 2021 19:10:24 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2021-11-03T19:10:24Z</dc:date>
    <item>
      <title>Global Protect not working with RADIUS NPS and LDAP on the same server.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445284#M100448</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a Firewall configured for Authentication for LDAP and RADIUS NPS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both works fine when I force the authentication profile using CLI:&lt;/P&gt;&lt;P&gt;test authentication authentication-profile LDAP username user password&lt;/P&gt;&lt;P&gt;test authentication authentication-profile RADIUS username user password&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, when using Global Protect with an Authentication Sequence, I see the RADIUS Auth Denied in the Event Viewer in Windows and the connection fails in the client, so it doesn't go to the next Authentication Profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also wanted to use Groups. I have 2 in Active Directory (RADIUS_Users and LDAP_Users) but I can only use Group Mapping for the LDAP, so RADIUS has no option to match a specific group. Any workaround for this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 16:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445284#M100448</guid>
      <dc:creator>JorgeOrtega</dc:creator>
      <dc:date>2021-11-03T16:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not working with RADIUS NPS and LDAP on the same server.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445332#M100450</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197310"&gt;@JorgeOrtega&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication sequence should check both authentication profiles regardless of the AAA response -&amp;gt; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMdXCAW" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMdXCAW&lt;/A&gt;.&amp;nbsp; (The link on the bottom of that link provides more details.)&amp;nbsp; I would double check that the user is not failing via LDAP also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regard to groups, you can configure groups in the authentication profile under Advanced.&amp;nbsp; The groups configured under Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; [edit group] &amp;gt; Group Include List will show in the authentication profile.&amp;nbsp; The firewall does an LDAP query for the group and gets the users.&amp;nbsp; If the login username matches, then the profile is used.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With regard to NPS, the Event Log &amp;gt; Security should tell you why it is failing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 18:29:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445332#M100450</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-11-03T18:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not working with RADIUS NPS and LDAP on the same server.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445342#M100451</link>
      <description>&lt;P&gt;Hi Tom,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the detailed response. I have two groups and I want the RADIUS Authentication Profile to use the RADIUS_NPS group in Active Directory. I also want the LDAP Authentication Profile to use the LDAP group in Active Directory.&lt;/P&gt;&lt;P&gt;The Authentication sequence is using RADIUS first and LDAP second and the idea is a user that belongs to the RADIUS group in AD should hit this Authentication Profile first and users that belongs to the LDAP group in AD should bypass the RADIUS and goes to the LDAP instead. Will this work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When following that link for the group mapping, I can only create one group for LDAP as this is the only Authentication Profile I can select.&amp;nbsp;Now if I do this I can then select it in the Allow List under the Advanced &lt;SPAN&gt;authentication profile under Advanced tab&amp;nbsp;&lt;/SPAN&gt;as you mentioned, however when I do the same for the RADIUS authentication profile it only shows the LDAP group. Should I type the name of the group manually? For example:&amp;nbsp;CN=RADIUS_Users,CN=Users,DC=mydomain,DC=com ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the guidance on this matter.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 19:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445342#M100451</guid>
      <dc:creator>JorgeOrtega</dc:creator>
      <dc:date>2021-11-03T19:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not working with RADIUS NPS and LDAP on the same server.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445344#M100452</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197310"&gt;@JorgeOrtega&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, that will worked based upon the allow list.&amp;nbsp; No, you shouldn't have to type it in manually as long as you can see it under&amp;nbsp; Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; [edit group] &amp;gt; Group Include List.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 19:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445344#M100452</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-11-03T19:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not working with RADIUS NPS and LDAP on the same server.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445365#M100454</link>
      <description>&lt;P&gt;I just checked that the only way that I can add groups to the Allow List below is by creating the Group Mapping. (right now both are using All):&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JorgeOrtega_0-1635972653031.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37488i6ED4D9F0B52439AB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="JorgeOrtega_0-1635972653031.png" alt="JorgeOrtega_0-1635972653031.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However still wondering why you select the RADIUS-NPS group shown below along with the LDAP one...&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JorgeOrtega_1-1635972742126.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37489i63FDF89830015B17/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="JorgeOrtega_1-1635972742126.png" alt="JorgeOrtega_1-1635972742126.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I only see the option for LDAP under the Server Profile for the same Group Mapping rule?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JorgeOrtega_3-1635972858155.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37491i271E5E29BBCDF4AA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="JorgeOrtega_3-1635972858155.png" alt="JorgeOrtega_3-1635972858155.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have no option to do Group Mapping of my RADIUS_NPS group to be under the NPS Server Profile only under the LDAP Server Profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jorge.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 20:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445365#M100454</guid>
      <dc:creator>JorgeOrtega</dc:creator>
      <dc:date>2021-11-03T20:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not working with RADIUS NPS and LDAP on the same server.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445388#M100459</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/197310"&gt;@JorgeOrtega&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is correct.&amp;nbsp; The firewall uses LDAP for group mapping.&amp;nbsp; That is the only (and correct) selection.&amp;nbsp; You do not need to specify the group under the server profile.&amp;nbsp; As long as you can modify the allow list in the authentication profile, it will work as desired.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 23:16:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445388#M100459</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-11-03T23:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect not working with RADIUS NPS and LDAP on the same server.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445395#M100461</link>
      <description>&lt;P&gt;Tom, I want to thank you for your valuable help. This worked like a charm. I had some issues in my setup that I discovered while I was creating the group mapping. I could also understand how these groups works. I created an RADIUS group and left All for the LDAP, so only a specific group that belongs to this group will have 2FA. Thanks again and have a great evening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Jorge.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 23:38:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-not-working-with-radius-nps-and-ldap-on-the-same/m-p/445395#M100461</guid>
      <dc:creator>JorgeOrtega</dc:creator>
      <dc:date>2021-11-03T23:38:02Z</dc:date>
    </item>
  </channel>
</rss>

