<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP / PA GUI fault in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/477364#M103661</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have Palo running within a EVENG environment.&lt;/P&gt;&lt;P&gt;I have set up Global Protect, the problem seems to be every time I try to log into GP using an AD account. I am automatically logged out of the Palo GUI. Furthermore, the username/password does not even authenticate, even though the un/pw is correct,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone had this problem ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
    <pubDate>Thu, 31 Mar 2022 19:20:15 GMT</pubDate>
    <dc:creator>Vimz888</dc:creator>
    <dc:date>2022-03-31T19:20:15Z</dc:date>
    <item>
      <title>GP / PA GUI fault</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/477364#M103661</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I currently have Palo running within a EVENG environment.&lt;/P&gt;&lt;P&gt;I have set up Global Protect, the problem seems to be every time I try to log into GP using an AD account. I am automatically logged out of the Palo GUI. Furthermore, the username/password does not even authenticate, even though the un/pw is correct,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone had this problem ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 19:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/477364#M103661</guid>
      <dc:creator>Vimz888</dc:creator>
      <dc:date>2022-03-31T19:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: GP / PA GUI fault</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/477394#M103667</link>
      <description>&lt;P&gt;It sounds to me like there are a few multiple issues going on.&amp;nbsp;&amp;nbsp;&amp;nbsp; Let's start with the GP user... if you have the correct user/pass and it fails, have you configured to use a local account (and NOT a local admin account), but local user database user.&amp;nbsp; You may want to try that first.&amp;nbsp; If that works but fails with AD, then you may want to check your service account, credentials, IP, as this would be the last/final place to look.&lt;BR /&gt;As for the login to the GUI, please try to use 2 different browser instances (not 2 browser tabs)&lt;/P&gt;&lt;P&gt;I have seen this on my own computer, where I get logged out when I have same browser, but 2 tabs.&amp;nbsp; I get logged out.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2022 00:01:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/477394#M103667</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-04-01T00:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: GP / PA GUI fault</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/477957#M103714</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried using another instance of the browser (chrome), but had the same issue. It logged me out straight away.&lt;/P&gt;&lt;P&gt;- just for clarity, I was using :4443 for the GUI portal and :443 for GP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Used a completely different browser (Edge), AND that did RESOLVE the issue - my question is why would it sign you out on the same browser, it's using different ports.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;With regard to the authentication locally, that is working fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to log into GP with the un/pw set locally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;name VPN1 passwordE1&amp;gt; test authentication authentication-profile AUTH-Local user&lt;BR /&gt;Enter password :&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "VPN1" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;name "VPN1" is in group "all"&lt;/P&gt;&lt;P&gt;Authentication by Local User Database for user "VPN1"&lt;/P&gt;&lt;P&gt;Authentication succeeded for Local User Database user "VPN1"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==&lt;/P&gt;&lt;P&gt;I tested the authentication of the UN/PW and this is the output I get,&amp;nbsp;&lt;/P&gt;&lt;P&gt;AD is connected, I can authenticate the username/password on the machine that are connected to the domain. It is only GP that does not want to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rname GPuser password test authentication authentication-profile AUTHPROFILE use&lt;BR /&gt;Enter password :&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "GPuser" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;user "paloeveng.local\GPuser" is a member of allowed group "cn=paloalto,ou=firewall,dc=paloeveng,dc=local" on vsys "vsys1"&lt;BR /&gt;Authentication to LDAP server at 192.168.150.10 for user "GPuser"&lt;BR /&gt;Egress: 192.168.22.10&lt;BR /&gt;Type of authentication: plaintext&lt;BR /&gt;Starting LDAP connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;Received empty DN for user "GPuser"&lt;BR /&gt;Authentication failed against LDAP server at 192.168.150.10:389 for user "GPuser"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Authentication failed for user "GPuser"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure what this is indicating&amp;nbsp;&lt;/P&gt;&lt;P&gt;Received empty DN for user "GPuser"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 14:55:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/477957#M103714</guid>
      <dc:creator>Vimz888</dc:creator>
      <dc:date>2022-04-04T14:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: GP / PA GUI fault</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/478025#M103719</link>
      <description>&lt;P&gt;After further looking into this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;less mp-log authd.log&lt;/P&gt;&lt;P&gt;2022-04-04 16:34:52.266 +0100 debug: _get_auth_prof_detail(pan_auth_util.c:1099): non-admin user thru Global Protect "GPuser" ; auth profile "AUTHPROFILE" ; vsys "vsys1"&lt;BR /&gt;2022-04-04 16:34:52.266 +0100 debug: _get_authseq_profile(pan_auth_util.c:886): Auth profile/vsys (AUTHPROFILE/vsys1) is NOT auth sequence&lt;BR /&gt;2022-04-04 16:34:52.266 +0100 debug: _retrieve_svr_ids(pan_auth_service.c:645): could not find auth server id vector for AUTHPROFILE-vsys1-mfa&lt;BR /&gt;2022-04-04 16:34:52.266 +0100 debug: add_info_from_auth_profile_to_request(pan_auth_util.c:1055): MFA is not configured for the auth profile. No mfa server ids for the user "" (prof/vsys: AU&lt;BR /&gt;THPROFILE/vsys1)&lt;BR /&gt;2022-04-04 16:34:52.266 +0100 debug: add_info_from_auth_profile_to_request(pan_auth_util.c:1066): MFA configured, but bypassed for GP user ''. (prof/vsys: AUTHPROFILE/vsys1)&lt;BR /&gt;uest-&amp;gt;username&lt;BR /&gt;2022-04-04 16:34:52.268 +0100 debug: pan_auth_cache_user_is_allowed(pan_auth_cache_allowlist_n_grp.c:569): This is a single vsys platform, group check for allow list is performed on "vsys1"&lt;BR /&gt;2022-04-04 16:34:52.271 +0100 debug: _authenticate_by_localdb_or_remote_server(pan_auth_state_engine.c:1835): Authenticating user "GPuser" with &amp;lt;profile: "AUTHPROFILE", vsys: "vsys1"&amp;gt;&lt;BR /&gt;2022-04-04 16:34:52.271 +0100 debug: _retrieve_svr_ids(pan_auth_service.c:648): find auth server id vector for AUTHPROFILE-vsys1&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;2022-04-04 16:34:52.273 +0100 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1132): searching basedn "DC=paloeveng, DC=local" for filter "(uid=GPuser)", attrs "framedIPAddress",&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;LDAPp=0x559d6c17c670&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2022-04-04 16:34:52.338 +0100 Error: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1193): Received empty DN for user "GPuser". Try to re-establish the connection&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2022-04-04 16:34:52.338 +0100 debug: pan_authd_ldap_authenticate(pan_authd_shared_ldap.c:1328): binding back to binddn: paservice@paloeveng.local (Try 1)&lt;BR /&gt;2022-04-04 16:34:52.338 +0100 debug: pan_authd_ldap_bind(pan_authd_shared_ldap.c:637): binding with binddn paservice@paloeveng.local&lt;BR /&gt;2022-04-04 16:34:52.358 +0100 Error: _start_sync_auth(pan_auth_service_handle.c:749): sync request for user "GPuser" is failed or possibly timed out against 192.168.150.10:389 with 0th VOID&lt;BR /&gt;p=0x559d6c17c670&lt;BR /&gt;gine.c:4322): auth status: auth state unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strolled through the basedn on AD, which was correct&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_3-1649091054600.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40020i1044E601709091FE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_3-1649091054600.png" alt="Vimz888_3-1649091054600.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After looking into it further via&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpoCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClpoCAC&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There was a misconfiguration on the LDAP profile, which caused the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_0-1649090489028.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40017i07D7000967DA291A/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_0-1649090489028.png" alt="Vimz888_0-1649090489028.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Changed the following&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_1-1649090522697.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40018iE85816495C1F6FFD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_1-1649090522697.png" alt="Vimz888_1-1649090522697.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The "Type" was set to "other" instead of "active-directory"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Vimz888_2-1649090551274.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/40019i53AA3BBBF87122B4/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Vimz888_2-1649090551274.png" alt="Vimz888_2-1649090551274.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and I hope this helps anyone having the same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 16:54:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-pa-gui-fault/m-p/478025#M103719</guid>
      <dc:creator>Vimz888</dc:creator>
      <dc:date>2022-04-04T16:54:01Z</dc:date>
    </item>
  </channel>
</rss>

