<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cli access with email usernames in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/458002#M101869</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;so I just test what you suggest with the ssh -l its the something. I can to screen prompting me to enter the password as soon as I enter the password the screen goes back to &lt;A href="mailto:username@domain.com@ipaddress" target="_blank" rel="noopener"&gt;username@domain.com@ipaddress&lt;/A&gt;&amp;nbsp;password:&amp;nbsp; and if I enter the password again I get a connection closed by ip address port 22. I think think the problem here is how its setup on the TACACS side.&lt;/P&gt;&lt;P&gt;As for the need, there are multiple domains and we have admins on different domains.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Tue, 11 Jan 2022 16:47:20 GMT</pubDate>
    <dc:creator>samisu</dc:creator>
    <dc:date>2022-01-11T16:47:20Z</dc:date>
    <item>
      <title>cli access with email usernames</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/457830#M101850</link>
      <description>&lt;P&gt;Has anyone been able to authenticate to the CLI using a username such as &lt;A href="mailto:username@domain.com" target="_blank" rel="noopener"&gt;username@domain.com&lt;/A&gt;&amp;nbsp;over SSH using TACACS+ as authentication. Authenticating using the WebUI works fine, but when you try to SSH using ssh &lt;A href="mailto:username@domain.com@ipaddress" target="_blank" rel="noopener"&gt;username@domain.com@ipaddress&lt;/A&gt;&amp;nbsp;it just sends you back to the username screen. ( user is a superadmin role)&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jan 2022 19:27:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/457830#M101850</guid>
      <dc:creator>samisu</dc:creator>
      <dc:date>2022-01-10T19:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: cli access with email usernames</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/457929#M101855</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200594"&gt;@samisu&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;- What do you mean by "back to username screen"? Do you mean password prompt"&lt;/P&gt;
&lt;P&gt;- I was thinking that two "@" could confuse the ssh command and it is not able to identify which part is username and which hostname, but I just test it and it seems it shouldn't be a problem. However just for the test, try to connect with "ssh -l &lt;A href="mailto:username@domain.com" target="_blank"&gt;username@domain.com&lt;/A&gt; ipaddress"&lt;/P&gt;
&lt;P&gt;- What firewall system logs are showing when you try to login with ssh? Does it show the whole username "username@domain.com"?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On other hand - do you really need for the user to enter domain when accessing firewall management? If your TACACS is expecting username in the form of "username@domain.com", you can create Authentication Profile that will append the domain to the user input&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_1-1641899966961.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/38567i8C13EF9DA715082A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_1-1641899966961.png" alt="Astardzhiev_1-1641899966961.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 11:19:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/457929#M101855</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-01-11T11:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: cli access with email usernames</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/457972#M101863</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200594"&gt;@samisu&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;This&amp;nbsp;&lt;EM&gt;should&amp;nbsp;&lt;/EM&gt;work just based off of a quick test that I did as long as they SSH client being utilized isn't escaping anything. When you look at the logs (System -&amp;gt; (subtype eq auth)) do you see the proper user being submitted?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 15:26:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/457972#M101863</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-01-11T15:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: cli access with email usernames</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/458002#M101869</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;so I just test what you suggest with the ssh -l its the something. I can to screen prompting me to enter the password as soon as I enter the password the screen goes back to &lt;A href="mailto:username@domain.com@ipaddress" target="_blank" rel="noopener"&gt;username@domain.com@ipaddress&lt;/A&gt;&amp;nbsp;password:&amp;nbsp; and if I enter the password again I get a connection closed by ip address port 22. I think think the problem here is how its setup on the TACACS side.&lt;/P&gt;&lt;P&gt;As for the need, there are multiple domains and we have admins on different domains.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 11 Jan 2022 16:47:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/458002#M101869</guid>
      <dc:creator>samisu</dc:creator>
      <dc:date>2022-01-11T16:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: cli access with email usernames</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/458003#M101870</link>
      <description>&lt;P&gt;there is no logs in the PAN device showing any successful authentication. The logs from the TACACS server show it authenticated successfully. This points me to what I was thinking before. There is some type of miss configuration on the TACACS side. Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 16:49:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cli-access-with-email-usernames/m-p/458003#M101870</guid>
      <dc:creator>samisu</dc:creator>
      <dc:date>2022-01-11T16:49:56Z</dc:date>
    </item>
  </channel>
</rss>

