<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help on Global Protect using LDAP Authentication.. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/help-on-global-protect-using-ldap-authentication/m-p/27165#M19819</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possibly your AD server prohibits plain text auth (simple bind). Modify server config to allow simple bind or setup SSL. Defer to your Server Team for assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 Jan 2013 15:45:51 GMT</pubDate>
    <dc:creator>gswcowboy</dc:creator>
    <dc:date>2013-01-17T15:45:51Z</dc:date>
    <item>
      <title>Help on Global Protect using LDAP Authentication..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-on-global-protect-using-ldap-authentication/m-p/27163#M19817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I been having trouble with GP authentication using LDAP server..&lt;/P&gt;&lt;P&gt;It seems like if i didnt set the SSL on the LDAP configuration, the AD is not able to communicate with the PAN..&lt;/P&gt;&lt;P&gt;Even if i did set both of non SSL or SSL, it still didnt show any users and authentication at GP page failed..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tail mp-log useridd.log&lt;/P&gt;&lt;P&gt;Jan 17 16:56:24 Error: pan_ldap_ctrl_connect(pan_ldap_ctrl.c:795): pan_ldap_bind()&amp;nbsp; failed&lt;/P&gt;&lt;P&gt;Jan 17 16:56:24 Error: pan_gm_data_connect_ctrl(pan_group_mapping.c:786): pan_ldap_ctrl_connect(XXX-AD, 10.12.1.1:389) failed&lt;/P&gt;&lt;P&gt;Jan 17 16:56:24 Error: pan_gm_data_connect_ctrl(pan_group_mapping.c:853): ldap cfg Pixart-AD failed connecting to server 10.12.1.1 index 0&lt;/P&gt;&lt;P&gt;Jan 17 16:56:24 Error: pan_gm_data_ldap_proc(pan_group_mapping.c:1168): pan_gm_data_connect_ctrl() failed&lt;/P&gt;&lt;P&gt;Jan 17 16:57:24 connected to ldap server ldap://10.12.1.1&lt;/P&gt;&lt;P&gt;Jan 17 16:57:24 Error: pan_ldap_bind_simple(pan_ldap.c:431): ldap_sasl_bind result return(8) : Strong(er) authentication required&lt;/P&gt;&lt;P&gt;Jan 17 16:57:24 Error: pan_ldap_ctrl_connect(pan_ldap_ctrl.c:795): pan_ldap_bind()&amp;nbsp; failed&lt;/P&gt;&lt;P&gt;Jan 17 16:57:24 Error: pan_gm_data_connect_ctrl(pan_group_mapping.c:786): pan_ldap_ctrl_connect(XXX-AD, 10.12.1.1:389) failed&lt;/P&gt;&lt;P&gt;Jan 17 16:57:24 Error: pan_gm_data_connect_ctrl(pan_group_mapping.c:853): ldap cfg XXX-AD failed connecting to server 10.12.1.1 index 0&lt;/P&gt;&lt;P&gt;Jan 17 16:57:24 Error: pan_gm_data_ldap_proc(pan_group_mapping.c:1168): pan_gm_data_connect_ctrl() failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It stated that this connection need stronger authentication... What does this means? My password is only simple for the AD bind password.&lt;/P&gt;&lt;P&gt;I try use LDAP communication testing software, it i didnt set SSL authentication,it will shows me error (Stronger authentication required) just same as PAN log.&lt;/P&gt;&lt;P&gt;Is anyone encountered this before?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 09:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-on-global-protect-using-ldap-authentication/m-p/27163#M19817</guid>
      <dc:creator>samsk</dc:creator>
      <dc:date>2013-01-17T09:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Help on Global Protect using LDAP Authentication..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-on-global-protect-using-ldap-authentication/m-p/27164#M19818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have a certificate installed on your domain controller ?&lt;/P&gt;&lt;P&gt;The certificate is needed to create the SSL tunnel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 15:35:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-on-global-protect-using-ldap-authentication/m-p/27164#M19818</guid>
      <dc:creator>JohanL</dc:creator>
      <dc:date>2013-01-17T15:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Help on Global Protect using LDAP Authentication..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/help-on-global-protect-using-ldap-authentication/m-p/27165#M19819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Possibly your AD server prohibits plain text auth (simple bind). Modify server config to allow simple bind or setup SSL. Defer to your Server Team for assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2013 15:45:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/help-on-global-protect-using-ldap-authentication/m-p/27165#M19819</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2013-01-17T15:45:51Z</dc:date>
    </item>
  </channel>
</rss>

