<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using LDAP/AD names for firewall GUI login in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46798#M34402</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, been out an about&lt;/P&gt;&lt;P&gt;I suggest you contact support - it does not sound right.&amp;nbsp; I think we'll definitely need pictures here &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure we could get this solved&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Jan 2011 23:40:40 GMT</pubDate>
    <dc:creator>James</dc:creator>
    <dc:date>2011-01-20T23:40:40Z</dc:date>
    <item>
      <title>Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46793#M34397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I believe I've successfully set up LDAP authentication in our Palo device. All of our groups and users are appearing when searched for using "show user ldap-server server all" and they show up in Authentication Profiles when changing the Allow List.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have added my user account from our AD domain into the LDAP Authentication Profile as detailed in the "eDirectory and LDAP Authentication with PANOS" document, but I'm not sure how to progress in getting this to be used for authorisation when logging into the firewall itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I go into create a new administrator account, the authentication profile drop-down only lists "None" - I had imagined this would let me specify a user based on LDAP but it seems not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I barking up the wrong tree, or should I be able to authenticate to the admin GUI using LDAP users? If so is there a step I'm missing in enabling this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John Bousfield&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 15:48:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46793#M34397</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-01-18T15:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46794#M34398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For this to work - you should have your LDAP server as a choice in the drop down.&lt;/P&gt;&lt;P&gt;The "Name" section would be your username in the LDAP server.&amp;nbsp; You would need to make an entry like this for each administrator.&amp;nbsp; This is OK for a small number of Admins.&lt;/P&gt;&lt;P&gt;If you expect to have many - then please check out this document using RADIUS and VSA's:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/docs/DOC-1701"&gt;https://live.paloaltonetworks.com/docs/DOC-1701&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jan 2011 17:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46794#M34398</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-18T17:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46795#M34399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James&lt;/P&gt;&lt;P&gt;Thanks for your reply. That's how I imagined it should work and doing it for each user manually is fine for now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when I go in to add the new administrator account I'm unable to select anything other than "None" - there is no option for my other Authorisation profiles (including a RADIUS profile already set up).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The help system indicates the same thing you have which is that I should have the list of Auth Profiles there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could there be some setting I've missed to enable new users to use all Auth Profiles?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jan 2011 10:18:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46795#M34399</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-01-19T10:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46796#M34400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it definitely Auth and not server profiles that you have configured?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen shot 2011-01-19 at 11.50.39.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/2137_Screen shot 2011-01-19 at 11.50.39.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jan 2011 11:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46796#M34400</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-19T11:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46797#M34401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James&lt;/P&gt;&lt;P&gt;I've got both Server Profile and Authentication Profiles configured. Tried to attach an image of these but it doesn't seem to let me...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server Profile has the LDAP servers listed and I can do looks ups to AD so those seem fine. User Idenfitication is also in place and seems to be working fine getting groups and users when I check via the command line.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Authentication Profiles include the one for LDAP, one for LocalDB and one for RADIUS at the moment. The LDAP Auth profile uses the LDAP Server Profile above, includes my AD account and an AD group in the Allow List and has sAMAccountName as the login attribute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of the Auth Profiles appear in the drop-down though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate any help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Jan 2011 12:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46797#M34401</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-01-19T12:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46798#M34402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, been out an about&lt;/P&gt;&lt;P&gt;I suggest you contact support - it does not sound right.&amp;nbsp; I think we'll definitely need pictures here &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure we could get this solved&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Jan 2011 23:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46798#M34402</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-20T23:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46799#M34403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James&lt;/P&gt;&lt;P&gt;I'll raise a support issue with our support contact directly but I have also attached the images of each config page to the post so you can have a quick browse of the settings I've got in place.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2011 10:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46799#M34403</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-01-21T10:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46800#M34404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For reference the problem was that my LDAP Server Profile and LDAP Authorisation Profiles were set to use VSYS but needed to be set to as Shared - you can't use Vsys profiles to authorise administrative users, which makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can't be altered once a profile is made so I removed both profiles and recreated as shared (tick box near the top of the form).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can now use LDAP to authorise users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jan 2011 10:03:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46800#M34404</guid>
      <dc:creator>aveva_palo</dc:creator>
      <dc:date>2011-01-26T10:03:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using LDAP/AD names for firewall GUI login</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46801#M34405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good news!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jan 2011 14:53:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-ldap-ad-names-for-firewall-gui-login/m-p/46801#M34405</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-01-26T14:53:22Z</dc:date>
    </item>
  </channel>
</rss>

