<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP Authentication not working when using include group settings in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455548#M101593</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had configured LDAP authentication on Palo alto firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The LDAP server had been configured and we had checked the connectivity and it was successful. Created an group mapping and included an group in the include group mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked the groups and the user details via CLI of the firewall and could see that&amp;nbsp;the user under the included group configurations is&amp;nbsp; being fetched by the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When configuring authentication profile we could see that the group is included in the authentication profile but the user in the group is not being authenticated but when the allow list is selected as all under the authentication profile the Authentication is happening properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tamilvanan.&lt;/P&gt;</description>
    <pubDate>Mon, 27 Dec 2021 16:18:40 GMT</pubDate>
    <dc:creator>tamilvanan</dc:creator>
    <dc:date>2021-12-27T16:18:40Z</dc:date>
    <item>
      <title>LDAP Authentication not working when using include group settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455548#M101593</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had configured LDAP authentication on Palo alto firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The LDAP server had been configured and we had checked the connectivity and it was successful. Created an group mapping and included an group in the include group mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checked the groups and the user details via CLI of the firewall and could see that&amp;nbsp;the user under the included group configurations is&amp;nbsp; being fetched by the firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When configuring authentication profile we could see that the group is included in the authentication profile but the user in the group is not being authenticated but when the allow list is selected as all under the authentication profile the Authentication is happening properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tamilvanan.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 16:18:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455548#M101593</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-12-27T16:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication not working when using include group settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455564#M101596</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;What I have seen is that somethings dont like nested groups. List the groups by itself and not nested and see if it works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 27 Dec 2021 17:58:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455564#M101596</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-12-27T17:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication not working when using include group settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455690#M101601</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does the username format in the "show user ip-user-mapping all" command match the username format in the "show user group name cn=blah,cn=blah,dc=blah,dc=blah" command?&amp;nbsp; (The "show user group list" command will give you the exact group name for the previous command.)&amp;nbsp; If the format does not match &lt;EM&gt;exactly&lt;/EM&gt;, then the user may not be matched to the group.&amp;nbsp; There are some things you can do to fix the issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Make sure the domain specified under Device &amp;gt; Authentication Profile &amp;gt; [LDAP Authenticaton Profile] &amp;gt; Authentication &amp;gt; User Domain matches the domain under Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; [edit] &amp;gt; Server Profile.&lt;/LI&gt;&lt;LI&gt;Follow the guidelines in this doc -&amp;gt; &lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/user-id-features/support-for-multiple-username-formats" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/user-id-features/support-for-multiple-username-formats&lt;/A&gt;.&amp;nbsp; The primary and alternate usernames can fix it as well as the matching without domains if the domain is different or missing.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 15:38:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455690#M101601</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-12-28T15:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication not working when using include group settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455703#M101603</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/77347"&gt;@TomYoung&lt;/a&gt;&amp;nbsp; Thanks for providing your valuable inputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After posting this issue I was searching for documentation on this issue and came across the doc mentioned .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the Authentication profile and Group mapping settings we had defined abc.com the full DNS name in the domain box. We had modified it to abc on both Group mapping and the Auth profile and the users in that particular groups started getting authenticated when testing using the test auth-profile command.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;STRONG&gt;&lt;U&gt;&lt;SPAN&gt;Global Protect&amp;nbsp;Login Fails When Using a Group in the Allow List&lt;/SPAN&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&lt;A href="http://webdefence.global.blackspider.com/urlwrap/?q=AXicHY1BCsIwEAC3T_DgN9JUQawgNcabR_1AbEMN2WZjslr0O4LvtDrnYWam4F0VUM8LSPiUSy9yeojBOGwpcCIULQ1Q7U_1ms83uZD1qoZowpjvMVLiXbKdCz1TmEThAlyZY96UpQ80ou16ezHZimiQDE6W5ZGSz79qedQnldi1aA-Wp2Pjuq1XlezlH43upZUGgE9TwBd7izfN&amp;amp;Z" target="_blank" rel="noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 28 Dec 2021 16:33:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455703#M101603</guid>
      <dc:creator>tamilvanan</dc:creator>
      <dc:date>2021-12-28T16:33:10Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication not working when using include group settings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455721#M101605</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/165087"&gt;@tamilvanan&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's exactly what I said in #1 above!&amp;nbsp; Glad you got it working.&amp;nbsp; BTW, your URL points to webdefense.&amp;nbsp; You may want to fix it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 17:01:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-not-working-when-using-include-group/m-p/455721#M101605</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2021-12-28T17:01:52Z</dc:date>
    </item>
  </channel>
</rss>

