<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User is not in allowlist in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31595#M23099</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to edit the allow list.&amp;nbsp; These links should answer your problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-message-small" href="https://live.paloaltonetworks.com/message/1779#1779"&gt;https://live.paloaltonetworks.com/message/1779#1779&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-message-small" href="https://live.paloaltonetworks.com/message/3103#3103"&gt;https://live.paloaltonetworks.com/message/3103#3103&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Sep 2010 21:47:22 GMT</pubDate>
    <dc:creator>James</dc:creator>
    <dc:date>2010-09-27T21:47:22Z</dc:date>
    <item>
      <title>User is not in allowlist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31594#M23098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Running PAN 2020 v3.1.4 using LDAP authentication with eDirectory.&amp;nbsp; I have a userid that will not authenticate via Captive portal. I am seeing a " User is not in allowlist" error in the System Log. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have verified that the userid in quesiton is in Server group.&amp;nbsp; That Server Group is referenced by a Security policy as the source User.&amp;nbsp; I have verified using "show user ldap-server server all" that the username in question does appear in the list on the paloalto.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As an FYI this same userid authenticates fine via the ldap agent.&amp;nbsp; If I run a show user ip-user-mapping for the IP address of a system that is logged in via the agent it correctly shows the userid as being in the group called out by a security policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this point, I am not seeing what is holding this up.&amp;nbsp; If that userid has logged in via the agent already on another box, would that somehow prevent that userid from logging in via captive portal on another system?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What should I be checking to troubleshoot this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 21:01:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31594#M23098</guid>
      <dc:creator>will74103</dc:creator>
      <dc:date>2010-09-27T21:01:11Z</dc:date>
    </item>
    <item>
      <title>Re: User is not in allowlist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31595#M23099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to edit the allow list.&amp;nbsp; These links should answer your problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-message-small" href="https://live.paloaltonetworks.com/message/1779#1779"&gt;https://live.paloaltonetworks.com/message/1779#1779&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-message-small" href="https://live.paloaltonetworks.com/message/3103#3103"&gt;https://live.paloaltonetworks.com/message/3103#3103&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Sep 2010 21:47:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31595#M23099</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2010-09-27T21:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: User is not in allowlist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31596#M23100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try adding the user directly to the allowlist instead of using the group?&amp;nbsp; Not permanently, but just to ensure that the general mapping is working.&amp;nbsp; If that works, then it's something to do with group enumeration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tariq&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 16:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31596#M23100</guid>
      <dc:creator>rahmant</dc:creator>
      <dc:date>2010-09-28T16:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: User is not in allowlist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31597#M23101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got the problem resolved.&amp;nbsp;&amp;nbsp; This particular userid had not been added to the group referenced by the Authentication policy. Once added, it began working.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a new installation and I simply forgot that the Authentication policy references an LDAP group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Sep 2010 17:46:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-is-not-in-allowlist/m-p/31597#M23101</guid>
      <dc:creator>will74103</dc:creator>
      <dc:date>2010-09-28T17:46:37Z</dc:date>
    </item>
  </channel>
</rss>

