<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP/ LDAP authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/450493#M101055</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication is against the below:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_2-1638304296321.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37864iD75F0692B07BA629/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_2-1638304296321.png" alt="Vimz888_2-1638304296321.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_3-1638304341383.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37865iABADF56314397D02/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_3-1638304341383.png" alt="Vimz888_3-1638304341383.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a user called "gpuser" is part of this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_4-1638304738111.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37866i03BAA8D5FB69EC1C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_4-1638304738111.png" alt="Vimz888_4-1638304738111.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I try to authenticate the user "gpuser" against AD, i get the following message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-SITE1&amp;gt; test authentication authentication-profile AUTHPROFILE username gpuser password&lt;BR /&gt;Enter password :&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "gpuser" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;user "paloeveng.local\gpuser" is a member of allowed group "cn=paloalto,ou=firewall,dc=paloeveng,dc=local" on vsys "vsys1"&lt;BR /&gt;Authentication to LDAP server at 192.168.150.10 for user "gpuser"&lt;BR /&gt;Egress: 192.168.22.10&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;Received empty DN for user "gpuser"&lt;BR /&gt;Authentication failed against LDAP server at 192.168.150.10:389 for user "gpuser"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authentication failed for user "gpuser"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I am not sure what this bit means "Received empty DN for user "gpuser""&lt;/P&gt;&lt;P&gt;If you need anymore info, let me know.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Nov 2021 20:53:14 GMT</pubDate>
    <dc:creator>Vimz888</dc:creator>
    <dc:date>2021-11-30T20:53:14Z</dc:date>
    <item>
      <title>GP/ LDAP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/450193#M101014</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a test AD/PA setup.&lt;/P&gt;&lt;P&gt;AD and LDAP connectivity is okay so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My problem is that I am unable to authenticate any user against Global Protect.&lt;/P&gt;&lt;P&gt;The un/pw are correct.&lt;/P&gt;&lt;P&gt;The group are correct too, as far as I can see.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the output i get when trying to authenticate:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SITE1&amp;gt; test authentication authentication-profile AUTHPROFILE username paloeveng.local\gpuser password&lt;BR /&gt;Enter password :&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "paloeveng.local\gpuser" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;user "paloeveng.local\gpuser" is a member of allowed group "cn=paloalto,ou=firewall,dc=paloeveng,dc=local" on vsys "vsys1"&lt;BR /&gt;Authentication to LDAP server at 192.168.150.10 for user "paloeveng.local\gpuser"&lt;BR /&gt;Egress: 192.168.22.10&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;Received empty DN for user "gpuser"&lt;BR /&gt;Authentication failed against LDAP server at 192.168.150.10:389 for user "paloeveng.local\gpuser"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authentication failed for user "paloeveng.local\gpuser"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;SITE1&amp;gt; show user group name "cn=paloalto,ou=firewall,dc=paloeveng,dc=local"&lt;/P&gt;&lt;P&gt;short name: paloeveng.local\paloalto&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: Paloeveng-profile&lt;/P&gt;&lt;P&gt;[1 ] paloeveng.local\gpuser&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;===========&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What am i missing within the config?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Nov 2021 22:10:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/450193#M101014</guid>
      <dc:creator>Vimz888</dc:creator>
      <dc:date>2021-11-29T22:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: GP/ LDAP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/450308#M101029</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/176672"&gt;@Vimz888&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Have you verified the actual authentication profile that you're attempting to utilize? That's really where I would be focusing my attention on.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have sAMAccountName for the Login Attribute? Do you specify your User Domain or Username Modifier?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 02:14:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/450308#M101029</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-30T02:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: GP/ LDAP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/450493#M101055</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication is against the below:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_2-1638304296321.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37864iD75F0692B07BA629/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_2-1638304296321.png" alt="Vimz888_2-1638304296321.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_3-1638304341383.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37865iABADF56314397D02/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_3-1638304341383.png" alt="Vimz888_3-1638304341383.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a user called "gpuser" is part of this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_4-1638304738111.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37866i03BAA8D5FB69EC1C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_4-1638304738111.png" alt="Vimz888_4-1638304738111.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When I try to authenticate the user "gpuser" against AD, i get the following message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-SITE1&amp;gt; test authentication authentication-profile AUTHPROFILE username gpuser password&lt;BR /&gt;Enter password :&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "gpuser" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;user "paloeveng.local\gpuser" is a member of allowed group "cn=paloalto,ou=firewall,dc=paloeveng,dc=local" on vsys "vsys1"&lt;BR /&gt;Authentication to LDAP server at 192.168.150.10 for user "gpuser"&lt;BR /&gt;Egress: 192.168.22.10&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;Received empty DN for user "gpuser"&lt;BR /&gt;Authentication failed against LDAP server at 192.168.150.10:389 for user "gpuser"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authentication failed for user "gpuser"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I am not sure what this bit means "Received empty DN for user "gpuser""&lt;/P&gt;&lt;P&gt;If you need anymore info, let me know.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Nov 2021 20:53:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/450493#M101055</guid>
      <dc:creator>Vimz888</dc:creator>
      <dc:date>2021-11-30T20:53:14Z</dc:date>
    </item>
    <item>
      <title>Re: GP/ LDAP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/477377#M103663</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how to resolve this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 20:29:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/477377#M103663</guid>
      <dc:creator>Vimz888</dc:creator>
      <dc:date>2022-03-31T20:29:46Z</dc:date>
    </item>
    <item>
      <title>Re: GP/ LDAP authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/1226543#M123991</link>
      <description>&lt;P&gt;May be you missed to add type under server setting of the LDAP server profile&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 09:34:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-ldap-authentication/m-p/1226543#M123991</guid>
      <dc:creator>CyberEye</dc:creator>
      <dc:date>2025-04-15T09:34:18Z</dc:date>
    </item>
  </channel>
</rss>

