<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: group-based policies for RADIUS authenticated users. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/453783#M101389</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I think this might be what you are looking for:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POFXCA4" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POFXCA4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluUCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluUCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 16 Dec 2021 22:13:46 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2021-12-16T22:13:46Z</dc:date>
    <item>
      <title>group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/453705#M101384</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For users who authenticate via RADIUS on Active Directory, is there any possibility to fetch the groups for those RADIUS users so that group-based policies can be created in the firewall?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 15:31:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/453705#M101384</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2021-12-16T15:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/453783#M101389</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I think this might be what you are looking for:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POFXCA4" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000POFXCA4&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluUCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluUCAS&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 16 Dec 2021 22:13:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/453783#M101389</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-16T22:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/455995#M101660</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I´m trying to do is to retrieve the group membership for RADIUS authenticated users in the AD. So that I can use the groups in the policies.&lt;/P&gt;&lt;P&gt;I´m trying to do a group mapping in some way like you do through LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 09:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/455995#M101660</guid>
      <dc:creator>Carracido</dc:creator>
      <dc:date>2021-12-30T09:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/456049#M101667</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Yes this is possible.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/authentication/configure-ldap-authentication" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/authentication/configure-ldap-authentication&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 15:43:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/456049#M101667</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-30T15:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562727#M113977</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;This KB is for LDAP and not for Radius like what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/24977"&gt;@Carracido&lt;/a&gt;&amp;nbsp;was after.&amp;nbsp; I am also having issues with Radius and retrieving user groups.&amp;nbsp; i have ticket the 'Retrieve user groups' in the auth profile and configure radius with what i believe are the correct VSA's as per&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIxCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIxCAK&amp;nbsp;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Unfortunately i still cannot pull any groups up to panorama/firewall.&amp;nbsp; Unfortunately this design cannot utilise LDAP at the moment so my options are limited.&amp;nbsp; Any suggestions?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 09:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562727#M113977</guid>
      <dc:creator>Alen_Bilich</dc:creator>
      <dc:date>2023-10-23T09:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562746#M113984</link>
      <description>&lt;P&gt;You can configure VSA's to use group membership to log into the firewall but Palo don't support using RADIUS groups in security policies.&lt;/P&gt;
&lt;P&gt;There is a feature request&amp;nbsp;FR2729 to add that capability.&lt;/P&gt;
&lt;P&gt;Ask your Palo SE to add a vote to it.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 12:15:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562746#M113984</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-10-23T12:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562747#M113985</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt;&amp;nbsp;thanks for the update.&amp;nbsp; in my case, the customer doesnt require security enforcement via policy.&amp;nbsp; At this stage we want to just pull the user groups up from radius and use the im the auth profile and subsequently the client config in GP.&amp;nbsp; If you have any advice, it would be appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 12:19:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562747#M113985</guid>
      <dc:creator>Alen_Bilich</dc:creator>
      <dc:date>2023-10-23T12:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562988#M114029</link>
      <description>&lt;P&gt;I did get this working but it took quite a lot of messing around so as to not break inadvertently what was working.&amp;nbsp; Not sure what the issue is on your end but in my case we did not have the USER DOMAIN field filled in or the RETRIEVE USER GROUP FROM RADIUS options checked.&amp;nbsp; I never went far enough with it to tell if I absolutely needed the domain in there but in my case this was what ultimately did the trick for me.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also the gateway or wherever the RADIUS group check is being done needs the full distinguished name to work properly.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 20:09:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/562988#M114029</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-10-24T20:09:19Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/563029#M114044</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/272860"&gt;@TonyDeHart&lt;/a&gt;&amp;nbsp;thanks for the info.&amp;nbsp; i have configured the user domain and ticked 'retrieve user groups' in the auth profile.&amp;nbsp; i have no issue with authenticating user with radius when 'All' is selected.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alen_Bilich_0-1698195508128.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54658i4ADFACDE0C1EE4F4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Alen_Bilich_0-1698195508128.png" alt="Alen_Bilich_0-1698195508128.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;VSA's configured on the radius for user group IT as an example.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alen_Bilich_1-1698195681366.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/54659iF9A666DF457824A2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Alen_Bilich_1-1698195681366.png" alt="Alen_Bilich_1-1698195681366.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;if anyone has any ideas, let me know.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 01:01:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/563029#M114044</guid>
      <dc:creator>Alen_Bilich</dc:creator>
      <dc:date>2023-10-25T01:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: group-based policies for RADIUS authenticated users.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/563113#M114060</link>
      <description>&lt;P&gt;I'm no expert on this, but what I was told when working with Palo support,was that the domain actually doesn't have any impact on the RADIUS authentication itself (in my case it is RSA) and that the domain and group info used is actually using the LDAP groups defined in the authentication profile to determine group membership. Without the domain configured it wasn't determining/matching the groups up with the auth profile and failed the membership check.&amp;nbsp; It was necessary for the groups to be included in the auth profile AND the domains to match.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry it was a detail I'd forgotten until I looked a bit closer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 12:10:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-based-policies-for-radius-authenticated-users/m-p/563113#M114060</guid>
      <dc:creator>TonyDeHart</dc:creator>
      <dc:date>2023-10-25T12:10:55Z</dc:date>
    </item>
  </channel>
</rss>

