<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Active Directory Users not Authenticating to GP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20982#M15323</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We configured agentless User-ID with our PAN OS 5.0.2. We created policies using the AD usernames and it is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, We are trying to configure our GP to authenticate using the AD users. This is not working and we are getting the following error when trying to login:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User is not in allowlist&lt;/P&gt;&lt;P&gt;description contains 'User \'abc\user1\' failed authentication.&amp;nbsp; Reason: User is not in allowlist From: 8.8.8.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then invalid user and password&lt;/P&gt;&lt;P&gt;description contains 'User \'abc\user1\' failed authentication.&amp;nbsp; Reason: Invalid username/password From: 8.8.8.8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are also regularly receiving this error:&lt;/P&gt;&lt;P&gt;( description contains 'ldap cfg ABC failed to connect to server 1.1.1.1:389, source: 2.2.2.2: Strong(er) authentication required' )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Allowlist.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15365_Allowlist.jpg" style="height: 627px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 08 Sep 2014 11:54:55 GMT</pubDate>
    <dc:creator>rsaber</dc:creator>
    <dc:date>2014-09-08T11:54:55Z</dc:date>
    <item>
      <title>Active Directory Users not Authenticating to GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20982#M15323</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We configured agentless User-ID with our PAN OS 5.0.2. We created policies using the AD usernames and it is working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, We are trying to configure our GP to authenticate using the AD users. This is not working and we are getting the following error when trying to login:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User is not in allowlist&lt;/P&gt;&lt;P&gt;description contains 'User \'abc\user1\' failed authentication.&amp;nbsp; Reason: User is not in allowlist From: 8.8.8.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then invalid user and password&lt;/P&gt;&lt;P&gt;description contains 'User \'abc\user1\' failed authentication.&amp;nbsp; Reason: Invalid username/password From: 8.8.8.8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are also regularly receiving this error:&lt;/P&gt;&lt;P&gt;( description contains 'ldap cfg ABC failed to connect to server 1.1.1.1:389, source: 2.2.2.2: Strong(er) authentication required' )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Allowlist.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15365_Allowlist.jpg" style="height: 627px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2014 11:54:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20982#M15323</guid>
      <dc:creator>rsaber</dc:creator>
      <dc:date>2014-09-08T11:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Users not Authenticating to GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20983#M15324</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like your serverprofile is enabled to use ssl while accessing the non-ssl port&lt;/P&gt;&lt;P&gt;you may need to review the authentication profile and correct the ldap information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it should look a little like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="15368" alt="2014-09-08_14-15-20.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15368_2014-09-08_14-15-20.png" style="height: 320px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2014 12:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20983#M15324</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2014-09-08T12:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Users not Authenticating to GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20984#M15325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Rsaber,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just for testing, Could you please let us know when &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;the allow list is set to 'all', the authentication succeed or not....? ( instead of defining a specific &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;groups/users).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2014 13:41:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20984#M15325</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-09-08T13:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Users not Authenticating to GP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20985#M15326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're not using the management server to reach your LDAP could be a service route issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6079"&gt;LDAP Authentication Fails When Using a User-ID Service Route&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Sep 2014 19:35:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-users-not-authenticating-to-gp/m-p/20985#M15326</guid>
      <dc:creator>GLastra</dc:creator>
      <dc:date>2014-09-08T19:35:39Z</dc:date>
    </item>
  </channel>
</rss>

