<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP Authentication questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16322#M11901</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I didn't understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying that if I have OpenLDAP to authenticate users in my company I don't need User-ID Agent/API to build security policy user based?&lt;/P&gt;&lt;P&gt;How can I get User-IP mapping in this situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Feb 2011 06:41:31 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-02-02T06:41:31Z</dc:date>
    <item>
      <title>LDAP Authentication questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16320#M11899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when I configure LDAP for authentication,&lt;BR /&gt;then I'm getting the groups in the distinguished name (dn) format.&lt;BR /&gt;I can choose them in policies and in the authentication profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my questions,&lt;BR /&gt;is the pan-agent then needed for policy authentication, too? Please explain why!&lt;BR /&gt;when I add a group in the dn format to the allow list&lt;BR /&gt;of an authentication profile, then it seems to be not matching when I'm trying to authenticate,&lt;BR /&gt;I have to add the users espacilly, is this right, or is the ldap connection not working correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 11:39:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16320#M11899</guid>
      <dc:creator>indevis</dc:creator>
      <dc:date>2010-12-02T11:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16321#M11900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you do not need to have pan agent to authenicate using ldap. it would seem like your ldap configuration is incorrect. please create a case and upload the tech support file for review of your ldap configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Dec 2010 16:27:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16321#M11900</guid>
      <dc:creator>jnguyen</dc:creator>
      <dc:date>2010-12-02T16:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16322#M11901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, I didn't understand.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying that if I have OpenLDAP to authenticate users in my company I don't need User-ID Agent/API to build security policy user based?&lt;/P&gt;&lt;P&gt;How can I get User-IP mapping in this situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2011 06:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16322#M11901</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-02-02T06:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16323#M11902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes you can authenticate users for SSL-VPN, Captive Portal!&lt;/P&gt;&lt;P&gt;Then you have to authenticate active with your user credentials.&lt;/P&gt;&lt;P&gt;And then you can use the LDAP groups in you policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if you want transparently authenticate the users,&lt;/P&gt;&lt;P&gt;then you are right you need the agent for the user-ip-mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is what I get, when I was testing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2011 07:35:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16323#M11902</guid>
      <dc:creator>indevis</dc:creator>
      <dc:date>2011-02-02T07:35:26Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16324#M11903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Feb 2011 09:00:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-questions/m-p/16324#M11903</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-02-02T09:00:27Z</dc:date>
    </item>
  </channel>
</rss>

