<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Web UI authentication LDAP fails in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67685#M39638</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured everything correct. But no entry in LDAP server security logs while I try to login paloalto Web UI using LDAP profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here at pan I can retrieve the all group user. I have configured the auth.&lt;/P&gt;
&lt;P&gt;Profile to 'all' entry in allow list..tried both domain\username(captive portal working fine with this format) and username alone..Pls suggest&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@paloalto&amp;gt; tail follow yes mp-log authd.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.826 +0530 debug:&lt;/P&gt;
&lt;P&gt;pan_auth_request_process(pan_auth_state_engine.c:1537): Trying to&lt;/P&gt;
&lt;P&gt;authenticate: &amp;lt;profile: "", vsys: "", username "cslworld\paloaltotest"&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.827 +0530 debug:&lt;/P&gt;
&lt;P&gt;_get_auth_prof_detail(pan_auth_util.c:928): "cslworld\paloaltotest" is an admin user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;pan_auth_cache_get_admin_authprof(pan_auth_cache_adminusers.c:222): No default auth profile found for username paloaltotest&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;_get_admin_authentication_profile_by_name(pan_auth_util.c:501): No admin auth prof found with the name paloaltotest&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;_get_admin_authentication_profile(pan_auth_util.c:546): No auth prof/vsys is found for admin user "paloaltotest"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;pan_get_authprofile_n_setting(pan_auth_util.c:1029): Failed to get authentication profile for admin cslworld\paloaltotest&lt;/P&gt;</description>
    <pubDate>Thu, 05 Nov 2015 08:03:21 GMT</pubDate>
    <dc:creator>Javith</dc:creator>
    <dc:date>2015-11-05T08:03:21Z</dc:date>
    <item>
      <title>Web UI authentication LDAP fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67685#M39638</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have configured everything correct. But no entry in LDAP server security logs while I try to login paloalto Web UI using LDAP profile.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here at pan I can retrieve the all group user. I have configured the auth.&lt;/P&gt;
&lt;P&gt;Profile to 'all' entry in allow list..tried both domain\username(captive portal working fine with this format) and username alone..Pls suggest&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@paloalto&amp;gt; tail follow yes mp-log authd.log&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.826 +0530 debug:&lt;/P&gt;
&lt;P&gt;pan_auth_request_process(pan_auth_state_engine.c:1537): Trying to&lt;/P&gt;
&lt;P&gt;authenticate: &amp;lt;profile: "", vsys: "", username "cslworld\paloaltotest"&amp;gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.827 +0530 debug:&lt;/P&gt;
&lt;P&gt;_get_auth_prof_detail(pan_auth_util.c:928): "cslworld\paloaltotest" is an admin user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;pan_auth_cache_get_admin_authprof(pan_auth_cache_adminusers.c:222): No default auth profile found for username paloaltotest&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;_get_admin_authentication_profile_by_name(pan_auth_util.c:501): No admin auth prof found with the name paloaltotest&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;_get_admin_authentication_profile(pan_auth_util.c:546): No auth prof/vsys is found for admin user "paloaltotest"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2015-11-05 12:35:02.849 +0530 Error:&lt;/P&gt;
&lt;P&gt;pan_get_authprofile_n_setting(pan_auth_util.c:1029): Failed to get authentication profile for admin cslworld\paloaltotest&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 08:03:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67685#M39638</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2015-11-05T08:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Web UI authentication LDAP fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67698#M39648</link>
      <description>&lt;P&gt;Can you share the authentication profile that you have created for the authentication to GUI.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Nov 2015 14:31:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67698#M39648</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-11-05T14:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Web UI authentication LDAP fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67796#M39677</link>
      <description>&lt;P&gt;Hi Kumar,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created the auth. profile in device tab with all entry in allow list as per kb.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the auth. profile in device-&amp;gt;setup tab?..on PAN-OS 7.0.3&lt;/P&gt;</description>
      <pubDate>Sun, 08 Nov 2015 16:20:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67796#M39677</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2015-11-08T16:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Web UI authentication LDAP fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67799#M39678</link>
      <description>&lt;P&gt;configured as per this KB:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Using-LDAP-to-Authenticate-to-the-Web-UI/ta-p/53445" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Using-LDAP-to-Authenticate-to-the-Web-UI/ta-p/53445&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 04:25:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67799#M39678</guid>
      <dc:creator>Javith</dc:creator>
      <dc:date>2015-11-09T04:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Web UI authentication LDAP fails</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67802#M39680</link>
      <description>&lt;P&gt;make sure that the authentication profile has a login attribute "sAMAcount" which is case sensitive, also when you add a new administrator add it only by username that is available in the LDAP server "note that there is no autocompletion" , the firewall will authenticate this user using the LDAP server.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 05:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/web-ui-authentication-ldap-fails/m-p/67802#M39680</guid>
      <dc:creator>AHlaiel</dc:creator>
      <dc:date>2015-11-09T05:59:54Z</dc:date>
    </item>
  </channel>
</rss>

