<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication profile + Kerberos + group restrictions - should work? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14809#M10878</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;did the support resolve your problem with using Groups with Kerberos authentication ? Can you post the solution ? Thanks !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2012 12:33:38 GMT</pubDate>
    <dc:creator>BLepenik</dc:creator>
    <dc:date>2012-05-30T12:33:38Z</dc:date>
    <item>
      <title>Authentication profile + Kerberos + group restrictions - should work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14807#M10876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Running 4.0.5 here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup SSL VPN a while ago, and setup an authentication profile to pull from our Active Directory via Kerberos.&amp;nbsp; I have an AD group and I only want the members of that group (or members of groups that are children of that master group) to have VPN access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I only add that single group to the allow list, and nothing else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some period of time, this was working correctly.&amp;nbsp; I have users that are in that group and could access the VPN, as well as users in sub-groups that could also access it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After some period of time, with zero changes to anything SSL-VPN or authentication related, this has stopped working.&amp;nbsp; I'm now getting a generic "invalid username or password" error, when it was working perfectly in the past.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I edit the authentication profile and remove the group restriction and instead change to "all," everything works again, but I am no longer restricting VPN access as I would like.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's going on here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found from searches that group restrictions are not supported with LDAP... but I'm using Kerberos and couldn't find anything about it one way or another.&amp;nbsp; If it is not supposed to work with group restrictions, how the heck was it working for me in the past!?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Oct 2011 06:38:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14807#M10876</guid>
      <dc:creator>bradenmcg</dc:creator>
      <dc:date>2011-10-27T06:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication profile + Kerberos + group restrictions - should work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14808#M10877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please could you open a case with the Support team so they may take a closer look. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Nov 2011 06:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14808#M10877</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2011-11-01T06:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication profile + Kerberos + group restrictions - should work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14809#M10878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;did the support resolve your problem with using Groups with Kerberos authentication ? Can you post the solution ? Thanks !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 12:33:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14809#M10878</guid>
      <dc:creator>BLepenik</dc:creator>
      <dc:date>2012-05-30T12:33:38Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication profile + Kerberos + group restrictions - should work?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14810#M10879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would be interested in a solution as well. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2012 08:10:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-profile-kerberos-group-restrictions-should-work/m-p/14810#M10879</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2012-10-01T08:10:30Z</dc:date>
    </item>
  </channel>
</rss>

