<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ldap groups not working in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5004#M3667</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I understand you need to make sure that you LDAP attibutes are in the correct case (I could be wrong)&lt;/P&gt;&lt;P&gt;In your "ldap_test_profile" the login attribute i think should be "sAMAccountName" and not "samaccountname" as displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Mar 2011 08:55:07 GMT</pubDate>
    <dc:creator>migration</dc:creator>
    <dc:date>2011-03-02T08:55:07Z</dc:date>
    <item>
      <title>ldap groups not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5002#M3665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for some reason we ( and many other customers ) are still experiencing issues regarding the use of ldap groups in an authenticatin profile for example SSL VPN.&lt;/P&gt;&lt;P&gt;We have microsoft AD as LDAP server and we went through every step in the well known following document ( eDirectory and LDAP authentication in PANOS 3 1 3.pdf)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we specify a single LDAP user in our authentication profile , we are able to authenticate with that user , but members of LDAP groups are not working as it should be.&lt;/P&gt;&lt;P&gt;I made a pdf document with printscreens of our configuration ( pdf document attached ). As you can see in the document , the PA is able to read the members of the group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please anyone who has good advice for us ( and many other customers ) to make this work ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks alot !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Securelink support !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Feb 2011 09:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5002#M3665</guid>
      <dc:creator>OCDBE</dc:creator>
      <dc:date>2011-02-04T09:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: ldap groups not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5003#M3666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like you are using the 4.0 BETA software. Is this correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you utilizing the SSL VPN client or the Global Protect client? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Feb 2011 23:17:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5003#M3666</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-02-07T23:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: ldap groups not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5004#M3667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I understand you need to make sure that you LDAP attibutes are in the correct case (I could be wrong)&lt;/P&gt;&lt;P&gt;In your "ldap_test_profile" the login attribute i think should be "sAMAccountName" and not "samaccountname" as displayed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 08:55:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5004#M3667</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-02T08:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: ldap groups not working</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5005#M3668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;in this case the domain needed to be removed from the ldap config since the domain only needs to be filled in when a panagent is also present&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Mar 2011 13:22:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-working/m-p/5005#M3668</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2011-03-02T13:22:21Z</dc:date>
    </item>
  </channel>
</rss>

