<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot log into firewall if authentication profile specifies an AD group instead of AD username in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-log-into-firewall-if-authentication-profile-specifies-an/m-p/491856#M104968</link>
    <description>&lt;P&gt;So last Thursday we upgraded our PA-5220s from 9.1.10 to 10.1.5-h1 and everything went incredibly well - absolutely no issues during the upgrade. About 15 hours after the upgrade was complete, we suddenly could not log onto the firewalls with our LDAP credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Typically we have an AD group specified in the Authentication profile we use for management access. If we keep that configuration, we cannot log into the firewalls. However, if we add individual AD users to the authentication profile, those users can log in with their LDAP credentials. I know the LDAP server profile is working because it is the same one used to allow Globalprotect users to authenticate, and that is working absolutely fine, and also uses AD groups.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked User-ID group mappings and we have our domains entire tree selected, so I know the group is available for mappings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are some sanitized screenshots of the config:&amp;nbsp;&lt;A href="https://imgur.com/a/6tuXgHu" target="_blank"&gt;https://imgur.com/a/6tuXgHu&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case open with TAC but our engineer is in a vastly different timezone and hasn't been able to find time on their shift to assist.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 May 2022 17:27:17 GMT</pubDate>
    <dc:creator>WinCo</dc:creator>
    <dc:date>2022-05-25T17:27:17Z</dc:date>
    <item>
      <title>Cannot log into firewall if authentication profile specifies an AD group instead of AD username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-log-into-firewall-if-authentication-profile-specifies-an/m-p/491856#M104968</link>
      <description>&lt;P&gt;So last Thursday we upgraded our PA-5220s from 9.1.10 to 10.1.5-h1 and everything went incredibly well - absolutely no issues during the upgrade. About 15 hours after the upgrade was complete, we suddenly could not log onto the firewalls with our LDAP credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Typically we have an AD group specified in the Authentication profile we use for management access. If we keep that configuration, we cannot log into the firewalls. However, if we add individual AD users to the authentication profile, those users can log in with their LDAP credentials. I know the LDAP server profile is working because it is the same one used to allow Globalprotect users to authenticate, and that is working absolutely fine, and also uses AD groups.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked User-ID group mappings and we have our domains entire tree selected, so I know the group is available for mappings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here are some sanitized screenshots of the config:&amp;nbsp;&lt;A href="https://imgur.com/a/6tuXgHu" target="_blank"&gt;https://imgur.com/a/6tuXgHu&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a case open with TAC but our engineer is in a vastly different timezone and hasn't been able to find time on their shift to assist.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 17:27:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-log-into-firewall-if-authentication-profile-specifies-an/m-p/491856#M104968</guid>
      <dc:creator>WinCo</dc:creator>
      <dc:date>2022-05-25T17:27:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot log into firewall if authentication profile specifies an AD group instead of AD username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-log-into-firewall-if-authentication-profile-specifies-an/m-p/496976#M105116</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44642"&gt;@WinCo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any information that can help you further in the authd logs or in the LDAP logs ?&lt;/P&gt;
&lt;P&gt;I know some default authentication behaviour changed from 9.1 to 10.x about the strict-username-check which might be worth checking:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/upgrade-pan-os/upgradedowngrade-considerations" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-new-features/upgrade-pan-os/upgradedowngrade-considerations&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2022 12:35:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-log-into-firewall-if-authentication-profile-specifies-an/m-p/496976#M105116</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2022-06-01T12:35:40Z</dc:date>
    </item>
  </channel>
</rss>

