<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect - PW Prompt when LDAP Auth is down. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67005#M39395</link>
    <description>&lt;P&gt;That makes sense. &amp;nbsp;I am wondering though why the client prompts for a password even though the client has checked off "remember me."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Oct 2015 13:41:22 GMT</pubDate>
    <dc:creator>mmclimans</dc:creator>
    <dc:date>2015-10-21T13:41:22Z</dc:date>
    <item>
      <title>GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66922#M39372</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried support on this, didn't get much help. &amp;nbsp;I am using PANOS 7.0 and GlobalProtect 2.2.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a couple hundred GlobalProtect clients using Windows. &amp;nbsp;I am using pre-logon (always on) with LDAP authentication. &amp;nbsp;The goal is to have the GlobalProtect clients to stay connected to the gateway &lt;U&gt;at all times&lt;/U&gt;, or keep trying to connect until a gateway becomes available. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The boxes auto-connect and auto-reconnect on their own 95% of the time. &amp;nbsp;However, in an event where the LDAP servers go down (i.e. maintenance or interruption), the user is prompted for a password even though pre-logon is being used and the user has selected "Remember me" within the client. &amp;nbsp;Please note, I am using certificates for pre-logon, but I can &lt;U&gt;not&lt;/U&gt; use&amp;nbsp;SSO. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have included a screenshot of the issue. &amp;nbsp;ANY HELP is appreciated. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client config&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/799iBF7754E0BA1EF1E9/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="snippet1.png" title="snippet1.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/800iB83363B6676D96EA/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="snippet2.png" title="snippet2.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Error on&amp;nbsp;client:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/801i0583CAC7FD41A6CB/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="snippet3.png" title="snippet3.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 19:44:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66922#M39372</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2015-10-20T19:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66938#M39380</link>
      <description>&lt;P&gt;If the LDAP server is down then how the firewall will authenticate. &amp;nbsp;As the LDAP is down so authentication fails so firewall is asking for&amp;nbsp;credentials again.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 22:12:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66938#M39380</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-10-20T22:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66940#M39381</link>
      <description>&lt;P&gt;How about setting up multiple ldap servers for redundancy? This way you can reboot one or more and still retain functinality.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 22:54:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66940#M39381</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2015-10-20T22:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66944#M39384</link>
      <description>&lt;P&gt;I am not sure if I understand what you mean by the firewall authenticating. &amp;nbsp;If you are referring to the admin login for the firewall that uses local authentication, not LDAP. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I am striving for is a truely "always on" solution. &amp;nbsp;In my view, when pre-logon says "always on" it should never ask the clients for credentials&amp;nbsp;when the authentication&amp;nbsp;server is down.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 03:13:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66944#M39384</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2015-10-21T03:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66945#M39385</link>
      <description>&lt;P&gt;Thanks for the reply. &amp;nbsp;I appreciate the recommendation. &amp;nbsp;We currently have two LDAP servers. &amp;nbsp;We have seen a couple of situations where the communication between the LDAP server and the clients becomes interrupted for one reason or another. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am wondering if there is some sort of registry setting for the Windows GP clients... something to supress the prompt?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 03:15:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66945#M39385</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2015-10-21T03:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66947#M39386</link>
      <description>&lt;P&gt;pre-logon vpn is a partial vpn that would allow a user to load logon scripts etc while the workstation boots into normal operational mode. This access is granted with a decreased level of authentication.&lt;/P&gt;
&lt;P&gt;Once the logon sequence completes the user will always be required to 'make himself known' by authenticating. the pre-logon vpn mode cannot be used while in normal windows 'desktop' mode.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To get around this you could try using an authentication sequence in the gateway configuration' authentication (instead of a single ldap profile) where two ldap profiles provide redundancy&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 07:14:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/66947#M39386</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-21T07:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67005#M39395</link>
      <description>&lt;P&gt;That makes sense. &amp;nbsp;I am wondering though why the client prompts for a password even though the client has checked off "remember me."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 13:41:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67005#M39395</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2015-10-21T13:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67010#M39396</link>
      <description>&lt;P&gt;that may require a little more troubleshooting, you'll first want to figure out what is happening to the ldap exactly.&lt;/P&gt;
&lt;P&gt;you could set up an wireshark on the ldap server or run a tcpdump on the firewall while testing a failed connection like this. maybe the ldap does respond to the authentication but in an unexpected way, making the Gateway reprompt the user for credentials because it thinks the authentication failed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the user/pass prompt would typically appear if something like that happens or if the password is changed or expired. GP debug log may help shed some light on this as well&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 14:38:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67010#M39396</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-10-21T14:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67303#M39495</link>
      <description>&lt;P&gt;I've opened this as a case with Palo Alto. &amp;nbsp;I will post my findings.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 13:53:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67303#M39495</guid>
      <dc:creator>mmclimans</dc:creator>
      <dc:date>2015-10-27T13:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect - PW Prompt when LDAP Auth is down.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67416#M39518</link>
      <description>&lt;P&gt;I point my ldap server at the root domain and not a single server, so it is setup as ldap server : corp.firm.local and it works without problems, the client querys whatever domain controller it can find.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 19:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-pw-prompt-when-ldap-auth-is-down/m-p/67416#M39518</guid>
      <dc:creator>markk96</dc:creator>
      <dc:date>2015-10-28T19:44:06Z</dc:date>
    </item>
  </channel>
</rss>

