<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN SSL - Verification of a login belonging to a AD group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14117#M10369</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Nov 2010 16:14:54 GMT</pubDate>
    <dc:creator>mjacobsen@paloaltonetworks.com</dc:creator>
    <dc:date>2010-11-10T16:14:54Z</dc:date>
    <item>
      <title>VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14111#M10363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi support,&lt;BR /&gt;&lt;BR /&gt;I have a question regarding the authentification of users through the VPN SSL.&lt;BR /&gt;&lt;BR /&gt;Here is the situation:&lt;BR /&gt;&lt;BR /&gt;Login of the SSL VPN user: &lt;STRONG&gt;AdminLogin&lt;BR /&gt;&lt;/STRONG&gt;Password of the SSL VPN user: &lt;STRONG&gt;AdminPass&lt;/STRONG&gt;&lt;BR /&gt; SSL VPN name: &lt;STRONG&gt;AdminSSLVPN&lt;/STRONG&gt;&lt;BR /&gt;Authentication Profile associated with &lt;STRONG&gt;AdminSSLVPN: AdminAuthProfil&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;AdminAuthProfil &lt;/STRONG&gt;authentication method: Radius server&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;STRONG&gt;AdminAuthProfil &lt;/STRONG&gt;allow list&lt;STRONG&gt;: DOMAIN\admin&lt;/STRONG&gt; (it's a AD group obtained by the user ID agent)&lt;STRONG&gt;. &lt;/STRONG&gt;&lt;STRONG&gt;AdminLogin &lt;/STRONG&gt;is a member of the&lt;STRONG&gt; &lt;/STRONG&gt;&lt;STRONG&gt;DOMAIN\admin &lt;/STRONG&gt;group&lt;STRONG&gt;.&lt;BR /&gt; &lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;When the login is submitted to the PAN, i would like to know how the verification of the belonging&amp;nbsp; of &lt;STRONG&gt;AdminLogin&lt;/STRONG&gt; to&lt;STRONG&gt; DOMAIN\admin&lt;/STRONG&gt; group is done. When a user is usually presented to the AD, the form of&amp;nbsp; the login is the following "DOMAIN\login". As the form of the login is&amp;nbsp; not the same in the AD and when a user log on to the SSL VPN how does it&amp;nbsp; works ? &lt;BR /&gt; &lt;BR /&gt;&lt;BR /&gt;When &lt;STRONG&gt;AdminLogin&lt;/STRONG&gt; connect to the SSL VPN, The PAN will check for the presence of &lt;STRONG&gt;AdminLogin &lt;/STRONG&gt;in the group &lt;STRONG&gt;DOMAIN\admin. &lt;/STRONG&gt;Or it will fail because the login is not presented like the AD form (&lt;STRONG&gt;DOMAIN\AdminLogin)&lt;/STRONG&gt;.&lt;STRONG&gt;&lt;BR /&gt; &lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;Thank you in advance.&lt;BR /&gt;&lt;BR /&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 10:29:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14111#M10363</guid>
      <dc:creator>novidys</dc:creator>
      <dc:date>2010-11-10T10:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14112#M10364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if your RADIUS profile has the domain field correctly configured with the domain name then the PA firewall will prepend the DOMAIN\ portion of the login when doing the RADIUS authentication process.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 14:40:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14112#M10364</guid>
      <dc:creator>pantac</dc:creator>
      <dc:date>2010-11-10T14:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14113#M10365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question was not concerning the stage of the authentification with the RADIUS but the stage after (authorisation).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's take the precedent exemple to explain our interrogation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From our understanding of the PAN when a user wants to connect to the SSL VPN there are several steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The user connect to the url of the VPN SSL&lt;/LI&gt;&lt;LI&gt;Submit his login and password&lt;/LI&gt;&lt;LI&gt;The radius server is first solicited for the authentication stage. The login and password are submitted from the PAN to the Radius server. The Radius then check if the password match for the login. Then is everything is OK the client is authenticated.&lt;/LI&gt;&lt;LI&gt;After that. There is the stage of the authorisation. The allow list which is associated to the VPN SSL (the user is connected on) is checked. The PAN verify if the login belongs to a group wich is specified in the allow list. This permit after to mount the SSL VPN for that user.&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding that. The authentication profil (&lt;STRONG&gt;AdminAuthProfil&lt;/STRONG&gt;) for the SSL VPN is configured like this this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Authentication method: RADIUS&lt;/LI&gt;&lt;LI&gt;Allow list: AD Groups taken from the User-ID agent. In the allow list we have &lt;STRONG&gt;DOMAIN\admin.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is (still regarding our exemple) :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When user connects to the SSL VPN the login that was submitted was &lt;STRONG&gt;AdminLogin &lt;/STRONG&gt;and not&lt;STRONG&gt; DOMAIN\AdminLogin.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when it's the turn of the authorisation stage. When &lt;STRONG&gt;AdminLogin&lt;/STRONG&gt; connect to the SSL VPN, The PAN will check for the presence of &lt;STRONG&gt;AdminLogin &lt;/STRONG&gt;in the group &lt;STRONG&gt;DOMAIN\admin&lt;/STRONG&gt; regarding the "allow list"&lt;STRONG&gt;. &lt;/STRONG&gt;Or it will fail because the login is not presented like the AD form (&lt;STRONG&gt;DOMAIN\AdminLogin)&lt;/STRONG&gt;.&lt;STRONG&gt;&lt;BR /&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 15:21:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14113#M10365</guid>
      <dc:creator>novidys</dc:creator>
      <dc:date>2010-11-10T15:21:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14114#M10366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you need to be running Pan Agent to retrieve the user/group mappings from your AD environment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 15:27:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14114#M10366</guid>
      <dc:creator>pantac</dc:creator>
      <dc:date>2010-11-10T15:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14115#M10367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The login will not fail. The system will use the domain string stored with the auth profile to infer the users domain (assuming they have not entered a fully qualified username). This will then map to the groups retrieved from the User Identification Agent and be matched in either the allow list in an auth profile or in security rules based on group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: mike&#xD;
&#xD;
EDIT: fixed a missing "not" in the comment about fully qualified username.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 15:32:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14115#M10367</guid>
      <dc:creator>mjacobsen@paloaltonetworks.com</dc:creator>
      <dc:date>2010-11-10T15:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14116#M10368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok mike.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if i reformulate your answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;If in my allow list, I have the following group: &lt;STRONG&gt;NOVIDYS\tech. &lt;/STRONG&gt;And in the AD, &lt;STRONG&gt;Bob &lt;/STRONG&gt;belongs to &lt;STRONG&gt;NOVIDYS.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;When &lt;STRONG&gt;Bob &lt;/STRONG&gt;want to connect to the SSL VPN he only submit &lt;STRONG&gt;Bob&lt;/STRONG&gt;. Then the PAN append &lt;STRONG&gt;NOVIDYS &lt;/STRONG&gt;to &lt;STRONG&gt;Bob &lt;/STRONG&gt;(&lt;STRONG&gt;"NOVIDYS\Bob"&lt;/STRONG&gt;) and check if he belongs to &lt;STRONG&gt;NOVIDYS\tech&lt;/STRONG&gt; (wich is in the allow list) regarding the information the Pan-agent gave to the PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left;"&gt;Best regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 15:59:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14116#M10368</guid>
      <dc:creator>novidys</dc:creator>
      <dc:date>2010-11-10T15:59:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14117#M10369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Nov 2010 16:14:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14117#M10369</guid>
      <dc:creator>mjacobsen@paloaltonetworks.com</dc:creator>
      <dc:date>2010-11-10T16:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN SSL - Verification of a login belonging to a AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14118#M10370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;But how to verify to which of the groups (from the firewall point of view) belongs the user being logged in?&lt;/P&gt;&lt;P&gt;Is there a CLI command like "show to which group belongs the user" ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Feb 2012 19:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vpn-ssl-verification-of-a-login-belonging-to-a-ad-group/m-p/14118#M10370</guid>
      <dc:creator>radoslaw.wal</dc:creator>
      <dc:date>2012-02-29T19:57:42Z</dc:date>
    </item>
  </channel>
</rss>

