<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Captive Portal -- LDAP Authentication Question in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-ldap-authentication-question/m-p/33096#M24254</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. I figured out the issue just now. I had to add the sAMAccountName value for Login Attribute under the LDAP Authentication Profile. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 Sep 2013 18:16:50 GMT</pubDate>
    <dc:creator>LouisScaringella</dc:creator>
    <dc:date>2013-09-16T18:16:50Z</dc:date>
    <item>
      <title>Captive Portal -- LDAP Authentication Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-ldap-authentication-question/m-p/33094#M24252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your time. I have a lab setup with a PA-500 and a Windows 2008 server with Active Directory. I have a single user in the trust zone on the Palo and I am trying to get Captive portal working for User-ID mappings of unknown users. I have my LDAP server profile and I have my user/group mappings working just fine with that, however, when I attempt to use the LDAP authentication profile in Device&amp;gt;User Identification&amp;gt;Captive Portal Settings which references that LDAP server profile, authentication fails.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user does get redirected to the web form and I put the credentials in and it fails to authenticate. When I do a packet capture on the Windows server, I see the LDAP bind request and it is successful. It then appears to be searching the directory and shows a success with 0 results. I am not too familiar with the inner workings of LDAP. Any ideas as to why authentication fails? I know I am entering in the correct username and password because I can login to the test domain I have setup on the host laptop. Does the username have to be in a certain format? I am not user SSL with LDAP in this scenario. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Sep 2013 17:19:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-ldap-authentication-question/m-p/33094#M24252</guid>
      <dc:creator>LouisScaringella</dc:creator>
      <dc:date>2013-09-16T17:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal -- LDAP Authentication Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-ldap-authentication-question/m-p/33095#M24253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my opinion You should start with check if you put netbios name of your AD domain in ldap profile.&lt;/P&gt;&lt;P&gt;This topic could be usefull for You &lt;A href="https://live.paloaltonetworks.com/thread/5050"&gt;problem with groups in user-id mapping&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check also system log for logs related to AD authentication. If You will sure that above is working You can start with Captive Portal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ANother thing - Make sure user identification is enabled on the ingress zone - please read &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1040"&gt;Troubleshooting Captive Portal &lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Sep 2013 18:13:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-ldap-authentication-question/m-p/33095#M24253</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-09-16T18:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Captive Portal -- LDAP Authentication Question</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-ldap-authentication-question/m-p/33096#M24254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. I figured out the issue just now. I had to add the sAMAccountName value for Login Attribute under the LDAP Authentication Profile. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Sep 2013 18:16:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/captive-portal-ldap-authentication-question/m-p/33096#M24254</guid>
      <dc:creator>LouisScaringella</dc:creator>
      <dc:date>2013-09-16T18:16:50Z</dc:date>
    </item>
  </channel>
</rss>

