<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Administrator Authentication with ldap in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4364#M3230</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chetan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the firewall does not support ldap authentication for non-local users. So even if showing successfully authenticated in the logs, It tries to look in to the administrator tab if there is any username of the same name which it authenticated. &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If we use custom name, it won't find the username and will show the error "invalid username or password". So that is why we need to create individual administrator profile corresponding to the name we authenticated or else use radius.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;IMG alt="radius.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14272_radius.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Aamir Khan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 Jul 2014 05:37:58 GMT</pubDate>
    <dc:creator>Westcon2</dc:creator>
    <dc:date>2014-07-03T05:37:58Z</dc:date>
    <item>
      <title>Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4350#M3216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Trying to create role based user account for monitoring the firewall. I tried to use ldap authentication. However it seems there is some issue with using ldap&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pix1.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14262_pix1.PNG" style="height: 503px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;I am facing this error after trying to authentication with correct credentials and below are the logs&lt;/P&gt;&lt;P&gt;&lt;IMG alt="pix2.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14263_pix2.PNG" style="height: 208px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;Although it shows authenticated, but still the invalid username and / or password on the GUI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it that it can't be done using ldap?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Aamir Khan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 00:55:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4350#M3216</guid>
      <dc:creator>Westcon2</dc:creator>
      <dc:date>2014-07-03T00:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4351#M3217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Aamir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please let us know the PAN OS version running on this PAN firewall and is the&amp;nbsp; username contains non-alphanumeric characters such as "/"...?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:05:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4351#M3217</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-03T01:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4352#M3218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may want to refer following document for more detail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5177"&gt;Defining Granular Admin Role Profiles&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:10:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4352#M3218</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-03T01:10:51Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4353#M3219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am using 6.0.3, however i test it on 6.0.1 with same result.The password is alpha numeric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:14:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4353#M3219</guid>
      <dc:creator>Westcon2</dc:creator>
      <dc:date>2014-07-03T01:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4354#M3220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Lets say you want to create Role based authentication for user Robert, than make sure Devcie &amp;gt; Administrator &amp;gt; &amp;amp; Name is Robert, if its different it will not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good news is it works with LDAP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:16:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4354#M3220</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-03T01:16:22Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4355#M3221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Role_Based2.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14267_Role_Based2.png" style="height: 282px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:18:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4355#M3221</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-03T01:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4356#M3222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Problem is I am not using predefined roles. I am having custom roles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:22:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4356#M3222</guid>
      <dc:creator>Westcon2</dc:creator>
      <dc:date>2014-07-03T01:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4357#M3223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="pix3.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14268_pix3.PNG" style="height: 232px; width: 620px;" /&gt;&lt;IMG alt="pix4.PNG" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14269_pix4.PNG" style="height: auto;" /&gt;&lt;IMG alt="pix5.PNG" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/14270_pix5.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:26:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4357#M3223</guid>
      <dc:creator>Westcon2</dc:creator>
      <dc:date>2014-07-03T01:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4358#M3224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Westcon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Custom Role and Standard Role, configuration is same. So I think that is not the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have runtime.in/iseadmin or iseadmin in Administrator filed? I think this is the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:26:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4358#M3224</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-03T01:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4359#M3225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Instead iseadmin can you try "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;runtime.in/iseadmin&lt;/SPAN&gt; " ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4359#M3225</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-03T01:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4360#M3226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;iseadmin is a user in ldap. However I want to give this user access to the firewall for monitoring only. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:30:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4360#M3226</guid>
      <dc:creator>Westcon2</dc:creator>
      <dc:date>2014-07-03T01:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4361#M3227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Westcon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For non local admins LDAP is not supported and only Radius is supported for remote login users. I tested this in lab and found similar results:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="14271" alt="Capture.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14271_Capture.PNG" style="height: 146px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;You can also see that in the window (Device &amp;gt; Setup &amp;gt; Authentication settings) while mentioning the authentication profile there is a statement that "Only Radius is supported"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chetan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:41:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4361#M3227</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-07-03T01:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4362#M3228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Harsha, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It did the trick having the username in the administrator profile. But the problem is if I have 3 users then I have to create 3 administrator profile each with the username.&lt;/P&gt;&lt;P&gt;I can't create a common template name&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.747 +0400 Running cmd: insert into admusers values (?, ?)&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.747 +0400 Error:&amp;nbsp; pan_authd_update_admin_user_in_db(pan_localdb_utils.c:186): Failed to add user:iseuser1 (uid:508) to /opt/pancfg/mgmt/global/db/admusers.db&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.747 +0400 debug: pan_authd_process_authresult(pan_authd.c:1353): pan_authd_process_authresult: runtime.in\iseuser1 authresult auth'ed&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.748 +0400 Request received to unlock shared/Ldap_admin/runtime.in\iseuser1&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.748 +0400 User 'runtime.in\iseuser1' authenticated.&amp;nbsp;&amp;nbsp; From: 80.227.87.218.&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.748 +0400 debug: pan_authd_generate_system_log(pan_authd.c:866): CC Enabled=False&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.749 +0400 debug: pan_authd_service_req(pan_authd.c:3322): Authd:get group request&lt;/P&gt;&lt;P&gt;2014-07-03 05:50:42.750 +0400 debug: pan_authd_handle_group_req(pan_authd.c:3210): Got user role/adomain / for user iseuser1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Aamir Khan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 01:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4362#M3228</guid>
      <dc:creator>Westcon2</dc:creator>
      <dc:date>2014-07-03T01:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4363#M3229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aamir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the same authentication profile for all the users. Can you explain in more detail why you cannot create a common template name ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Chetan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 02:30:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4363#M3229</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-07-03T02:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4364#M3230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chetan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the firewall does not support ldap authentication for non-local users. So even if showing successfully authenticated in the logs, It tries to look in to the administrator tab if there is any username of the same name which it authenticated. &lt;/P&gt;&lt;UL&gt;&lt;LI&gt;If we use custom name, it won't find the username and will show the error "invalid username or password". So that is why we need to create individual administrator profile corresponding to the name we authenticated or else use radius.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;IMG alt="radius.PNG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14272_radius.PNG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Aamir Khan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jul 2014 05:37:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4364#M3230</guid>
      <dc:creator>Westcon2</dc:creator>
      <dc:date>2014-07-03T05:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: Administrator Authentication with ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4365#M3231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have a windows server in the environment, you can add the RADIUS role and use this with the PA custom dictionary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1232"&gt;How to Configure Radius on Windows 2008&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1701"&gt;Configuring Administrator Authentication with Windows 2008 RADIUS Server (NPS/IAS)&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jul 2014 11:01:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/administrator-authentication-with-ldap/m-p/4365#M3231</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-07-04T11:01:07Z</dc:date>
    </item>
  </channel>
</rss>

