<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN OS 5.0 and AD authentication problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16338#M11917</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've had exactly the same problem - I worked through it with Palo support and we discovered we had to put the netbios domain name back in the LDAP query (the one we had to remove in 4.1.8) and then the group name had to be in the format domain\groupname rather than the full LDAP path. I also had spaces in the OU name for the account I was doing the LDAP lookup with and found we had to move this to a OU without a space in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Nov 2012 13:09:37 GMT</pubDate>
    <dc:creator>DaveM</dc:creator>
    <dc:date>2012-11-29T13:09:37Z</dc:date>
    <item>
      <title>PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16337#M11916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a little problem with my PA-5020. After upgrading OS to a 5.0 version my user authentication to log on as an administrator from ldap and kerberos doesn`t work. I had user mapped to an allowed list by AD group: &lt;/P&gt;&lt;P&gt;cn=administratorzy paloalto,ou=urzĄdzenia,ou=grupy zasobÓw,dc=my,dc=domain,dc=name, &lt;/P&gt;&lt;P&gt;it was working fine with os 4.X&amp;nbsp; but after updating to a 5.0 i got errors:&lt;/P&gt;&lt;P&gt;User 'my.domain.name\myuser' failed authentication.&amp;nbsp; Reason: User is not in allowlist From: x.x.x.x&lt;/P&gt;&lt;P&gt;After adding user directly ("my.domain.name\myuser") to allow list it works perfectly. &lt;/P&gt;&lt;P&gt;At first i thought it was problem with my OU names containing ó,ą which are polish letters, but i moved that group to a different OU without theme and it still doesn`t work. &lt;/P&gt;&lt;P&gt;It looks like PA doesn`t see members of my groups.&lt;/P&gt;&lt;P&gt;Weird thing is that I also have policy based on user belonging to a different groups and that mapping works fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 12:46:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16337#M11916</guid>
      <dc:creator>ArkadiuszMatalewski</dc:creator>
      <dc:date>2012-11-29T12:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16338#M11917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've had exactly the same problem - I worked through it with Palo support and we discovered we had to put the netbios domain name back in the LDAP query (the one we had to remove in 4.1.8) and then the group name had to be in the format domain\groupname rather than the full LDAP path. I also had spaces in the OU name for the account I was doing the LDAP lookup with and found we had to move this to a OU without a space in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 13:09:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16338#M11917</guid>
      <dc:creator>DaveM</dc:creator>
      <dc:date>2012-11-29T13:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16339#M11918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You it worked but its pretty annoying that i have to change my OU to let PA work properly i hope they will fix it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 14:26:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16339#M11918</guid>
      <dc:creator>ArkadiuszMatalewski</dc:creator>
      <dc:date>2012-11-29T14:26:54Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16340#M11919</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Making OUs with spaces is just asking for trouble &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Few CLI commands for debuging user/group mapping:&lt;/P&gt;&lt;P&gt;debug user-id reset group-mapping all&lt;/P&gt;&lt;P&gt;show user ip-user-mapping ip &amp;lt;IP address&amp;gt;&lt;/P&gt;&lt;P&gt;show user user-IDs match-user &amp;lt;user name&amp;gt;&lt;/P&gt;&lt;P&gt;show user group list&lt;/P&gt;&lt;P&gt;show user group name &amp;lt;group name&amp;gt;&lt;/P&gt;&lt;P&gt;General rule is: use NetBIOS style user/group names.&lt;/P&gt;&lt;P&gt;Run into problems myself when using FQDN (groups were retrieved in FQDN-style but not matched to users which were mapped to group in NetBIOS-style).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Dec 2012 15:40:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16340#M11919</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-12-03T15:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16341#M11920</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Albert &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you post a picture of your LDAP config from your firewall. I've having some logon issues with pre-logon and I think it might be related. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2012 15:32:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16341#M11920</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-12-07T15:32:24Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16342#M11921</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;djrodb - I could not paste a picture, would have to obfuscate it and that would not help you &lt;img id="smileywink" class="emoticon emoticon-smileywink" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-wink.png" alt="Smiley Wink" title="Smiley Wink" /&gt; But I exported the config to xml and edited it:&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ldap&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;entry name="&lt;STRONG&gt;AD-DCs&lt;/STRONG&gt;"&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;server&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;entry name="&lt;STRONG&gt;AD-PDC&lt;/STRONG&gt;"&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;port&amp;gt;&lt;STRONG&gt;389&lt;/STRONG&gt;&amp;lt;/port&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;address&amp;gt;&lt;STRONG&gt;10.10.10.10&lt;/STRONG&gt;&amp;lt;/address&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;entry name="&lt;STRONG&gt;AD-BDC&lt;/STRONG&gt;"&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;port&amp;gt;&lt;STRONG&gt;389&lt;/STRONG&gt;&amp;lt;/port&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;address&amp;gt;&lt;STRONG&gt;10.10.10.11&lt;/STRONG&gt;&amp;lt;/address&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/server&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ldap-type&amp;gt;&lt;STRONG&gt;active-director&lt;/STRONG&gt;y&amp;lt;/ldap-type&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;timelimit&amp;gt;&lt;STRONG&gt;30&lt;/STRONG&gt;&amp;lt;/timelimit&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;bind-timelimit&amp;gt;&lt;STRONG&gt;30&lt;/STRONG&gt;&amp;lt;/bind-timelimit&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;ssl&amp;gt;&lt;STRONG&gt;no&lt;/STRONG&gt;&amp;lt;/ssl&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;base&amp;gt;&lt;STRONG&gt;DC=imagine,DC=local&lt;/STRONG&gt;&amp;lt;/base&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;bind-dn&amp;gt;&lt;STRONG&gt;pa500@imagine&lt;/STRONG&gt;&amp;lt;/bind-dn&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;bind-password&amp;gt;&lt;STRONG&gt;Hashed_Password&lt;/STRONG&gt;&amp;lt;/bind-password&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;domain&amp;gt;&lt;STRONG&gt;imagine&lt;/STRONG&gt;&amp;lt;/domain&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;retry-interval&amp;gt;&lt;STRONG&gt;3&lt;/STRONG&gt;&amp;lt;/retry-interval&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/entry&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/ldap&amp;gt;&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;That is a working configuration for Active Directory domain &lt;STRONG&gt;imagine.local &lt;/STRONG&gt;with Primary and Backup Domain Controllers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you say more about your difficulties? What do you mean by "pre-logon"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2012 16:00:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16342#M11921</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-12-07T16:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16343#M11922</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Albert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pre-logon is a feature of the GP VPN client. The pre-logon function uses certificates and ldap authentication to lo the user into the laptop before you actually press crt alt del to log on. This allow you to run login scripts and patches on all remote laptops that come in via the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is the pre-logon feature isn't working 'pre logon' as I get user authentication errors. When I actually log onto the box and log in as normal the GP client logs me onto the network. So it works post-logon but not pre-logon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ldap setting match yours so it doesn't seem to be that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rod&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 08:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16343#M11922</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-12-10T08:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16344#M11923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;djrodb - Oh, it is a PAN-OS 5.0 feature (just checked it). I currently do not have any box on it in production so can not help you with any experience. However:&lt;/P&gt;&lt;P&gt;1. Have you configured pre-logon according to: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4209"&gt;https://live.paloaltonetworks.com/docs/DOC-4209&lt;/A&gt; ?&lt;/P&gt;&lt;P&gt;2. Have you tried configuring Kerberos authentication in place of LDAP?&lt;/P&gt;&lt;P&gt;3. What entries are in the log of the Global Protect client on the machine failing authentication?&lt;/P&gt;&lt;P&gt;I think you have problems related to certificates, as you can establish VPN using only LDAP credentials (method you use post-logon).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please keep me updated on your progress, this feature is interesting.&lt;/P&gt;&lt;P&gt;I will try to implement it in lab if time allows.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 09:28:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16344#M11923</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-12-10T09:28:29Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16345#M11924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Albert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've finally got this working. The problem was me settings in the GP portal config. I originally selected the LDAP group I'd configured under the user/user group setting in the GP portal client config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I changed this to any and it resolved the problem. This feature works really good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="4885" alt="pa.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/4885_pa.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 09:49:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16345#M11924</guid>
      <dc:creator>djrodb</dc:creator>
      <dc:date>2012-12-10T09:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16346#M11925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad you made it &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Dec 2012 09:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16346#M11925</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-12-10T09:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16347#M11926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Albert_C,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Could you show an example of how to specify the group you want to list with the command "&lt;/P&gt;&lt;P&gt;show user group name &amp;lt;group name&amp;gt;" ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Art&lt;/P&gt;&lt;P&gt;&lt;BR /&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Apr 2013 19:40:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16347#M11926</guid>
      <dc:creator>Art</dc:creator>
      <dc:date>2013-04-18T19:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16348#M11927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ArtBahrs - s&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;orry for the late replay, I was swamped with work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easiest is to type: &lt;EM&gt;show user group name&lt;/EM&gt; and press TAB - PAN CLI will show available choices (groups).&lt;/P&gt;&lt;P&gt;You can specify short and long format:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;show user group name example\bu-personal&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;is identical as:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;show user group name cn=bu-personal,ou=general,ou=groups,dc=example,dc=org&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If group contains spaces (or other unwanted characters) you will have to enclose it in double quotes:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;show user group name "cn=domain admins,cn=users,dc=example,dc=org"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;show user group name "example\domain admins"&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 14:35:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16348#M11927</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-23T14:35:01Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16349#M11928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG style="font-size: 10.666666984558105px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;Refer to &lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1162" data-externalid="" data-presence="null" data-userid="7279" data-username="djrodb" href="https://live.paloaltonetworks.com/people/djrodb" id="jive-727938166661768160686" style="padding: 0 3px 0 0; font-weight: inherit; font-style: inherit; font-size: 1.1em; font-family: inherit; text-decoration: underline; color: #316989;"&gt;djrodb&lt;/A&gt; &lt;/STRONG&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 10.666666984558105px; background-color: #ffffff;"&gt;Dec 10, 2012 1:50 AM &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 10.666666984558105px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 8pt; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;I would like to know logon script working on our GP Pre-logon. We had an issue that logon script is not working if we put group either&amp;nbsp; domain\user group or LADP format&amp;nbsp; cn=network_tech,ou=groups,dc=domain,dc=com but if we put any in source user in security rule and authentication profile it will works. For LADP config. We leave domain name empty which is suggested by Tech. GP user can authenticate without problem and go to network resource and map drive manually but logon scripts is not working. Please share your experience if possiable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 8pt; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 8pt; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 8pt; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 8pt; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Daniel&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 8pt; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 8pt; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="font-color-meta-light j-thread-replyto" style="padding: 0 0 0 3px; font-size: 10.666666984558105px; font-family: Arial, Helvetica, sans-serif; color: #a9a9a9; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 18:03:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16349#M11928</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2013-04-24T18:03:08Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16350#M11929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:daniel.li@tcdsb.org"&gt;daniel.li@tcdsb.org&lt;/A&gt;&lt;SPAN&gt; - if I understand you correctly Windows' logon scripts are not working when you put specific user or group in security rule?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Please refer to: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-2020"&gt;https://live.paloaltonetworks.com/docs/DOC-2020&lt;/A&gt; for comprehensive information about configuring GlobalProtect.&lt;/P&gt;&lt;P&gt;Reason why scripts are not working with specific user/group in security rule is:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;All pre-logon VPN connection will report a generic “pre-logon user” to User-ID. Username&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;is not known at the time the connection is established. Username is reported to gateway&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;once the user logs in to machine.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Taken from GlobalProtect Configuration Tech Note.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 18:40:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16350#M11929</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T18:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16351#M11930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Albert. There are two places to add user/group (authentication profile and security policy)&lt;/P&gt;&lt;P&gt;If both place are Any. logon script will NOT work in our case. I have not tried one Any one user/Group. Basically we only allow staff to get authenticated not Students. We followed Doc 2020 for setup. Is there fix to get logon script working with pre-logon SSO setting. My understanding for pre-logon with SSO&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. User (not in office network) with pre config wired or wilress internet connection, power up machine without logon window. Pre-logon is already established between user laptop GP client to PA portal&lt;/P&gt;&lt;P&gt;2. user login with AD user and GP starts to connect using AD user (SSO) and then user starts logon&amp;nbsp; corp domain/scripts/drive mapping &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if Palo Alto staff use pre-log feature to get home drive mapped at home. We use Juniper/Cisco and it works well. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 19:58:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16351#M11930</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2013-04-24T19:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16352#M11931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:daniel.li@tcdsb.org"&gt;daniel.li@tcdsb.org&lt;/A&gt;&lt;SPAN&gt; - What about the third place in which you can add user/group, GlobalProtect Portal Client Configuration? Does pre-logon is successfully establishing connection, apart from running scripts?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:28:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16352#M11931</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T20:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16353#M11932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;3rd place is default=Any, we did not touch 3rd place in our test.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:32:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16353#M11932</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2013-04-24T20:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16354#M11933</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry i missed the question everything is working except the script=drive mapping&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 20:33:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16354#M11933</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2013-04-24T20:33:47Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16355#M11934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:daniel.li@tcdsb.org"&gt;daniel.li@tcdsb.org&lt;/A&gt;&lt;SPAN&gt; - now I am utterly confused.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;First you wrote:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;We had an issue that logon script is not working if we put group either&amp;nbsp; domain\user group or LADP format&amp;nbsp; cn=network_tech,ou=groups,dc=domain,dc=com &lt;STRONG&gt;but if we put any in source user in security rule and authentication profile it will work&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Then:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;If both place are Any. logon script will NOT work in our case&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do not know what works for you, and what does not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 21:02:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16355#M11934</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-04-24T21:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 5.0 and AD authentication problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16356#M11935</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry. I had incorrect information in my previous emails&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Script working setting: Any/Any/Any setting in the 3 places (security policy/authentication profile --we used Radius/portal client configuration&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Script not working:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Domain/group name or cn=xxx format/domain/group name or cn=xxx/Any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: cn=xxxx are defined in Group mapping under User identification. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time to help on this issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Apr 2013 13:46:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-5-0-and-ad-authentication-problem/m-p/16356#M11935</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2013-04-25T13:46:50Z</dc:date>
    </item>
  </channel>
</rss>

