<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal with Radius and groups of users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25180#M18370</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from my understanding the option &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Retrieve user groups doesn't retrieve the groups and lists them on any tab. It's just so it will ask the radius server for the VSA #5 like you already linked. The Radius server will send the attribute back and has to match the "user" (groupname in auth profile)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never worked with FreeRadius but you could follow this guide &lt;A href="http://blog.davidvassallo.me/2010/09/15/adding-vendor-specific-radius-attributes-bluecoat-proxysg/" title="http://blog.davidvassallo.me/2010/09/15/adding-vendor-specific-radius-attributes-bluecoat-proxysg/"&gt;Adding vendor-specific RADIUS attributes (BlueCoat ProxySG) | David Vassallo's Blog&lt;/A&gt; and change everything to the Palo Alto attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no guaranty that this will work. I hope this helps a bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Dec 2014 16:42:36 GMT</pubDate>
    <dc:creator>Wenar</dc:creator>
    <dc:date>2014-12-04T16:42:36Z</dc:date>
    <item>
      <title>Captive Portal with Radius and groups of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25178#M18368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to consult with You one problem. My users authenticate with Radius on Captive Portal web page.&lt;/P&gt;&lt;P&gt;Problem that comes to me is how to assign access according to groups of users. My FreeRadius has only one group of users, I can add more but how to use it in PAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I read &lt;A href="https://live.paloaltonetworks.com/docs/DOC-2908"&gt;How to Configure RADIUS Authentication&lt;/A&gt; and there is "Retrieve user groups" checkbox but after I enabled it and do commit I cant see my groups in ADD in Authenticate Profile tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that I should use &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1765"&gt;RADIUS Vendor Specific Attributes (VSA)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PaloAlto-User-Group&lt;/STRONG&gt;: Attribute #5 - This is the name of the group to be used in the Authentication Profile&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do You know how to configure FreeRadius to use it? Please point me in right direction with this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Dec 2014 14:22:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25178#M18368</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-02T14:22:30Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with Radius and groups of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25179#M18369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;bump&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No one is using RAdius auth with groups pulling ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2014 15:23:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25179#M18369</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-04T15:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with Radius and groups of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25180#M18370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;from my understanding the option &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;Retrieve user groups doesn't retrieve the groups and lists them on any tab. It's just so it will ask the radius server for the VSA #5 like you already linked. The Radius server will send the attribute back and has to match the "user" (groupname in auth profile)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never worked with FreeRadius but you could follow this guide &lt;A href="http://blog.davidvassallo.me/2010/09/15/adding-vendor-specific-radius-attributes-bluecoat-proxysg/" title="http://blog.davidvassallo.me/2010/09/15/adding-vendor-specific-radius-attributes-bluecoat-proxysg/"&gt;Adding vendor-specific RADIUS attributes (BlueCoat ProxySG) | David Vassallo's Blog&lt;/A&gt; and change everything to the Palo Alto attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no guaranty that this will work. I hope this helps a bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Dec 2014 16:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25180#M18370</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2014-12-04T16:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with Radius and groups of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25181#M18371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I sow it before I posted this question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment I have one problem, and I cant find answer: Is is possible to use in security policies groups from Radius?&lt;/P&gt;&lt;P&gt;According to my knoweladge is it possible to limit authenticating to group defined in authentificate profile, but what next?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Dec 2014 08:55:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25181#M18371</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-08T08:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with Radius and groups of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25182#M18372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in my tests it didn't work to use radius groups in security rules. I think the device only looks up the groups for the user if they try to authenticate. After that the groups of the user are unknown. I didn't get an official answer from palo alto for this problem but I never had the request to use radius groups in policies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Dec 2014 09:15:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25182#M18372</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2014-12-08T09:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with Radius and groups of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25183#M18373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so&amp;nbsp; I wil lask my SE for confirmation, but this isnt a good news for me &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Dec 2014 10:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/25183#M18373</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-12-08T10:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal with Radius and groups of users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/133153#M47170</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you had confirmation about this ?&lt;/P&gt;&lt;P&gt;I trying to accomplish exactly the same thing but on globalprotect, and my group never match.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;2016-12-16 09:27:36.550 +1100 debug: pan_process_radius_auth(pan_authd.c:1115): Found radius group VPN_1 for user OCEAN\michel
2016-12-16 09:27:36.550 +1100 authentication succeeded for user &amp;lt;vsys1,FreeRadius,OCEAN\michel&amp;gt;
2016-12-16 09:27:36.551 +1100 authentication succeeded for remote user &amp;lt;OCEAN\michel(orig:michel)&amp;gt;
2016-12-16 09:27:36.551 +1100 debug: pan_authd_process_authresult(pan_authd.c:1353): pan_authd_process_authresult: OCEAN\michel authresult auth'ed
2016-12-16 09:27:36.551 +1100 Request received to unlock vsys1/VPN_Auth_ALL/OCEAN\michel
2016-12-16 09:27:36.552 +1100 User 'OCEAN\michel' authenticated. Profile FreeRadius in an authentication sequence VPN_Auth_ALL succeeded.  From: 203.147.79.6.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I use michel account to allow access to globalprotect it works.&lt;/P&gt;&lt;P&gt;If I use radius group "VPN_1" to allow access to globalprotect, nothing happen, even if pan retrieve correctly the name of the group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2016 22:39:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-with-radius-and-groups-of-users/m-p/133153#M47170</guid>
      <dc:creator>reseau.dtsi</dc:creator>
      <dc:date>2016-12-15T22:39:01Z</dc:date>
    </item>
  </channel>
</rss>

