<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Superuser (read-only) Not authorized to access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/594658#M118358</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200092"&gt;@MichaelBorg&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Try using superreader as the value, that's what the firewall actually uses on the backend.&lt;/P&gt;</description>
    <pubDate>Mon, 12 Aug 2024 21:49:41 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2024-08-12T21:49:41Z</dc:date>
    <item>
      <title>Superuser (read-only) Not authorized to access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/594636#M118352</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to get TACACS working between our PA and Aruba Clearpass authentication server. I have successfully done this for full admin as well as a custom role on the firewall. I am however running into issues with a service account logging in with read only access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I try to login to the local firewall with this service account I get the message "Not authorized to access" (please see screenshot PACLP1.PNG). This is further confirmed by the firewall systems logs (please see screenshot PACLP2.PNG). The role name that I specified in Clearpass is correct however, I copied and pasted the name from the local firewall account role into Clearpass so this should be fine&amp;nbsp;(please see screenshot PACLP3.PNG).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This worked fine with the local firewall account but something is wrong with the authorization of this Clearpass integration. Not sure if this matters but when the service account was local on the firewall and working it was using Radius but with this Clearpass integration I'm using TACACS. I don't think this is an issue as 2 different types of login (normal firewall superuser as well as a custom role) work fine. Can anyone please advise. Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 15:28:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/594636#M118352</guid>
      <dc:creator>MichaelBorg</dc:creator>
      <dc:date>2024-08-12T15:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Superuser (read-only) Not authorized to access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/594639#M118353</link>
      <description>&lt;P&gt;Update - I created a custom role on the firewall and made it as read-only as I can and that works fine. Am I not able to successfully reference the dynamic firewall&amp;nbsp;&lt;SPAN&gt;Superuser (read-only) role? This works for the dynamic Superuser role so I thought it would work.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 15:47:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/594639#M118353</guid>
      <dc:creator>MichaelBorg</dc:creator>
      <dc:date>2024-08-12T15:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Superuser (read-only) Not authorized to access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/594658#M118358</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/200092"&gt;@MichaelBorg&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Try using superreader as the value, that's what the firewall actually uses on the backend.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Aug 2024 21:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/594658#M118358</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-08-12T21:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Superuser (read-only) Not authorized to access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/595019#M118425</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry for the delay. Many thanks for that advise, I'll try that tomorrow and let you know.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 16:07:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/595019#M118425</guid>
      <dc:creator>MichaelBorg</dc:creator>
      <dc:date>2024-08-15T16:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Superuser (read-only) Not authorized to access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/595242#M118455</link>
      <description>&lt;P&gt;Thank you Bpry, adding superreader instead worked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 15:33:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/superuser-read-only-not-authorized-to-access/m-p/595242#M118455</guid>
      <dc:creator>MichaelBorg</dc:creator>
      <dc:date>2024-08-19T15:33:12Z</dc:date>
    </item>
  </channel>
</rss>

