<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues with Groups in Authentication Profile in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-groups-in-authentication-profile/m-p/2100#M1555</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am have an issue with the allow list on the Authentication Profile.&amp;nbsp; Up until yesterday I had an AD group name which pointer to the highest level of our tree and SSL-VPN users were not able to login, the message they got was "Invalid UserID and/or Password"&amp;nbsp; I changed the allow list to "all" and now everything works, but I would like to know why I can't use a group in the allow list.&amp;nbsp; These were all AD users in this group and we also have an administrators account set-up which would not use the Group "Local Users" in the allow list, so we had to insert individual users to the allow list or "All" and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to summarize, we are not able to use Groups in the allow list but we can use "all" or individual users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Mar 2011 12:31:53 GMT</pubDate>
    <dc:creator>brancwa</dc:creator>
    <dc:date>2011-03-02T12:31:53Z</dc:date>
    <item>
      <title>Issues with Groups in Authentication Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-groups-in-authentication-profile/m-p/2100#M1555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am have an issue with the allow list on the Authentication Profile.&amp;nbsp; Up until yesterday I had an AD group name which pointer to the highest level of our tree and SSL-VPN users were not able to login, the message they got was "Invalid UserID and/or Password"&amp;nbsp; I changed the allow list to "all" and now everything works, but I would like to know why I can't use a group in the allow list.&amp;nbsp; These were all AD users in this group and we also have an administrators account set-up which would not use the Group "Local Users" in the allow list, so we had to insert individual users to the allow list or "All" and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So to summarize, we are not able to use Groups in the allow list but we can use "all" or individual users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 12:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-groups-in-authentication-profile/m-p/2100#M1555</guid>
      <dc:creator>brancwa</dc:creator>
      <dc:date>2011-03-02T12:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Groups in Authentication Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-groups-in-authentication-profile/m-p/2101#M1556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are correct. We do not support the use of groups for Authentication Profiles using LDAP. The best option is to use RADIUS and all users. Our LDAP implementating is somewhat simple. If you create a user ID we can then use the credentials provided by the user to loginto ldap and confirm the password and user name. But this does not scale well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Steve Krall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 19:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-groups-in-authentication-profile/m-p/2101#M1556</guid>
      <dc:creator>skrall</dc:creator>
      <dc:date>2011-03-02T19:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with Groups in Authentication Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issues-with-groups-in-authentication-profile/m-p/2102#M1557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well, there are some things you could try with RADIUS for the administrators. If you have your PAN-device admins in a AD-group you could have that group in a Network Policy server/IAS-authentication profile. That should take care of the Administrators, You can even utilize the vendor-specific attributes to give your admins the right privileges! It's a bit crude, but it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When it comes to the your SSLVPN users. How have you set up Authentication ? LDAP, RADIUS? If LDAP, do you filter out the groups?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 20:50:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issues-with-groups-in-authentication-profile/m-p/2102#M1557</guid>
      <dc:creator>rapoint_person</dc:creator>
      <dc:date>2011-03-02T20:50:41Z</dc:date>
    </item>
  </channel>
</rss>

