<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect Radius Child Domains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-radius-child-domains/m-p/19448#M14203</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What happens if the user adds the prefix to the username to specify the child domain so that when the request is forwarded from the PAN firewall towards the RADIUS server the request is as follows&amp;nbsp; ChildDomain\username rather than the user just trying to authenticate with the username only?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 12 Apr 2014 22:30:50 GMT</pubDate>
    <dc:creator>sjamaluddin</dc:creator>
    <dc:date>2014-04-12T22:30:50Z</dc:date>
    <item>
      <title>Global Protect Radius Child Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-radius-child-domains/m-p/19447#M14202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Global Protect using Radius works perfect for users in the parent domain. It will not work for users in child domains.&lt;/P&gt;&lt;P&gt;I worked with Palo Support for several hours and they believe the issue is a setting on the Radius server but they do not know what the settings on the Radius server should be for child domains.&lt;/P&gt;&lt;P&gt;Does anyone know how to set the Radius server settings or have a DOC to it?&lt;/P&gt;&lt;P&gt;This is not an issue for my Cisco ASA...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 8.0pt;"&gt;14:45:02.165702 IP 192.168.165.241.54053 &amp;gt; Server.Parent.com.radius: RADIUS, Access Request (1), id: 0x4e length: 64&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt;"&gt;&lt;SPAN style="font-size: 8.0pt;"&gt;14:45:02.167058 IP &lt;SPAN style="font-size: 10.399999618530273px;"&gt;Server.Parent.com.&lt;/SPAN&gt;.radius &amp;gt; 192.168.165.241.54053: RADIUS, Access&lt;SPAN style="color: #575757;"&gt; &lt;STRONG&gt;Reject (3)&lt;/STRONG&gt;,&lt;/SPAN&gt; id: 0x4e length: 20&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Apr 2014 13:29:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-radius-child-domains/m-p/19447#M14202</guid>
      <dc:creator>ddavis1</dc:creator>
      <dc:date>2014-04-12T13:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Radius Child Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-radius-child-domains/m-p/19448#M14203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What happens if the user adds the prefix to the username to specify the child domain so that when the request is forwarded from the PAN firewall towards the RADIUS server the request is as follows&amp;nbsp; ChildDomain\username rather than the user just trying to authenticate with the username only?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Apr 2014 22:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-radius-child-domains/m-p/19448#M14203</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2014-04-12T22:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Radius Child Domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-radius-child-domains/m-p/19449#M14204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was finally able to get the user to authenticate to the web address to download the client by adding the specific path for the child domain users in the PA Authentication Profile and doing the same on the radius server. But it does not work for the global protect client. I would think since it authenticated the user to download the client it would have worked when connecting with global protect. &lt;/P&gt;&lt;P&gt;Yes have to use ChildDomain\UserName&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #5a6e7a; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px;"&gt;GlobalProtect portal user authentication failed. Login from: 70.210.1.8, User name: TestUser, Reason: Authentication failed: Invalid username or password &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Apr 2014 18:27:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-radius-child-domains/m-p/19449#M14204</guid>
      <dc:creator>ddavis1</dc:creator>
      <dc:date>2014-04-14T18:27:23Z</dc:date>
    </item>
  </channel>
</rss>

