<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global protect authentication LDAP not working fine in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101107#M44385</link>
    <description>&lt;P&gt;Hi, we have GlobalProtect configured using a LDAP group for authentication in the VPN "cn=groupvpnusers,ou=_generic_groups,dc=it,dc=xxxx,dc=local"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we commit this new config using vpn group in Auth profile, the GP authenticacion is working fine but 2-3 hours later it starts to fail and we get this error in all users in this group "&lt;SPAN&gt;failed authentication. Reason: User is not in allowlist". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To solve it we need to configure all in the "Auth profile" in order to &amp;nbsp;work again. We dont know why if we use a group in Auth profile the PA is working fine only 2-3 hours. ¿any timeout mapping?¿any refresh?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PanOS is 6.0.12&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the useridd.log after 2 hours using ldap groups for auth VPN:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2016-08-03 13:18:18.042 +0200 debug: pan_authd_service_req(pan_authd.c:3316): Authd:Trying to remote authenticate user: paloaltovpntest&lt;BR /&gt;2016-08-03 13:18:18.042 +0200 debug: pan_authd_service_auth_req(pan_authd.c:1158): AUTH Request &amp;lt;'vsys1','LDAP_USER_VPN_FR-1-1','paloaltovpntest'&amp;gt;&lt;BR /&gt;2016-08-03 13:18:18.045 +0200 panauth:user &amp;lt;it.xxxxxx.local\paloaltovpntest,LDAP_USER_VPN_FR-1-1,vsys1&amp;gt;&lt;STRONG&gt; is not allowed&lt;/STRONG&gt;&lt;BR /&gt;2016-08-03 13:18:18.045 +0200 debug: pan_authd_process_authresult(pan_authd.c:1353): pan_authd_process_authresult: &lt;SPAN&gt;it.xxxxxx.local&lt;/SPAN&gt;\paloaltovpntest authresult not auth'ed&lt;BR /&gt;2016-08-03 13:18:18.054 +0200 debug: pan_authd_process_authresult(pan_authd.c:1399): Alarm generation set to: False.&lt;BR /&gt;2016-08-03 13:18:18.054 +0200 User '&lt;SPAN&gt;it.xxxxxx.local&lt;/SPAN&gt;\paloaltovpntest' failed authentication. Reason: User is not in allowlist From: 88.3.65.25&lt;BR /&gt;2016-08-03 13:18:18.054 +0200 debug: pan_authd_generate_system_log(pan_authd.c:866): CC Enabled=False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is when its working (in this case using all in auth profile not ldap group)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2016-08-03 13:24:56.096 +0200 debug: pan_authd_service_req(pan_authd.c:3316): Authd:Trying to remote authenticate user: paloaltovpntest&lt;BR /&gt;2016-08-03 13:24:56.096 +0200 debug: pan_authd_service_auth_req(pan_authd.c:1158): AUTH Request &amp;lt;'vsys1','LDAP_USER_VPN_FR-1-1','paloaltovpntest'&amp;gt;&lt;BR /&gt;2016-08-03 13:24:56.098 +0200 debug: pan_authd_common_authenticate(pan_authd.c:1654): Authenticating user using&amp;nbsp;&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 debug: pan_authd_authenticate_service(pan_authd.c:629): authentication succeeded (0)&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 debug: pan_authd_authenticate_service(pan_authd.c:635): account is valid&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 authentication succeeded for user &amp;lt;vsys1,LDAP_USER_VPN_FR-1-1,it.xxxxxx..local\paloaltovpntest&amp;gt;&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 debug: pan_authd_process_authresult(pan_authd.c:1353): pan_authd_process_authresult: it.xxxxxxx..local\paloaltovpntest authresult auth'ed&lt;BR /&gt;2016-08-03 13:24:56.126 +0200 Request received to unlock vsys1/LDAP_USER_VPN_FR-1-1/it.xxxxxx.local\paloaltovpntest&lt;BR /&gt;2016-08-03 13:24:56.131 +0200 User 'it.xxxxxxx.local\paloaltovpntest' authenticated. From: 85..x.x.x&lt;/P&gt;</description>
    <pubDate>Thu, 11 Aug 2016 07:48:20 GMT</pubDate>
    <dc:creator>soporteseguridad</dc:creator>
    <dc:date>2016-08-11T07:48:20Z</dc:date>
    <item>
      <title>Global protect authentication LDAP not working fine</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101107#M44385</link>
      <description>&lt;P&gt;Hi, we have GlobalProtect configured using a LDAP group for authentication in the VPN "cn=groupvpnusers,ou=_generic_groups,dc=it,dc=xxxx,dc=local"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we commit this new config using vpn group in Auth profile, the GP authenticacion is working fine but 2-3 hours later it starts to fail and we get this error in all users in this group "&lt;SPAN&gt;failed authentication. Reason: User is not in allowlist". &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;To solve it we need to configure all in the "Auth profile" in order to &amp;nbsp;work again. We dont know why if we use a group in Auth profile the PA is working fine only 2-3 hours. ¿any timeout mapping?¿any refresh?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PanOS is 6.0.12&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the useridd.log after 2 hours using ldap groups for auth VPN:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2016-08-03 13:18:18.042 +0200 debug: pan_authd_service_req(pan_authd.c:3316): Authd:Trying to remote authenticate user: paloaltovpntest&lt;BR /&gt;2016-08-03 13:18:18.042 +0200 debug: pan_authd_service_auth_req(pan_authd.c:1158): AUTH Request &amp;lt;'vsys1','LDAP_USER_VPN_FR-1-1','paloaltovpntest'&amp;gt;&lt;BR /&gt;2016-08-03 13:18:18.045 +0200 panauth:user &amp;lt;it.xxxxxx.local\paloaltovpntest,LDAP_USER_VPN_FR-1-1,vsys1&amp;gt;&lt;STRONG&gt; is not allowed&lt;/STRONG&gt;&lt;BR /&gt;2016-08-03 13:18:18.045 +0200 debug: pan_authd_process_authresult(pan_authd.c:1353): pan_authd_process_authresult: &lt;SPAN&gt;it.xxxxxx.local&lt;/SPAN&gt;\paloaltovpntest authresult not auth'ed&lt;BR /&gt;2016-08-03 13:18:18.054 +0200 debug: pan_authd_process_authresult(pan_authd.c:1399): Alarm generation set to: False.&lt;BR /&gt;2016-08-03 13:18:18.054 +0200 User '&lt;SPAN&gt;it.xxxxxx.local&lt;/SPAN&gt;\paloaltovpntest' failed authentication. Reason: User is not in allowlist From: 88.3.65.25&lt;BR /&gt;2016-08-03 13:18:18.054 +0200 debug: pan_authd_generate_system_log(pan_authd.c:866): CC Enabled=False&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is when its working (in this case using all in auth profile not ldap group)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2016-08-03 13:24:56.096 +0200 debug: pan_authd_service_req(pan_authd.c:3316): Authd:Trying to remote authenticate user: paloaltovpntest&lt;BR /&gt;2016-08-03 13:24:56.096 +0200 debug: pan_authd_service_auth_req(pan_authd.c:1158): AUTH Request &amp;lt;'vsys1','LDAP_USER_VPN_FR-1-1','paloaltovpntest'&amp;gt;&lt;BR /&gt;2016-08-03 13:24:56.098 +0200 debug: pan_authd_common_authenticate(pan_authd.c:1654): Authenticating user using&amp;nbsp;&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 debug: pan_authd_authenticate_service(pan_authd.c:629): authentication succeeded (0)&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 debug: pan_authd_authenticate_service(pan_authd.c:635): account is valid&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 authentication succeeded for user &amp;lt;vsys1,LDAP_USER_VPN_FR-1-1,it.xxxxxx..local\paloaltovpntest&amp;gt;&lt;BR /&gt;2016-08-03 13:24:56.125 +0200 debug: pan_authd_process_authresult(pan_authd.c:1353): pan_authd_process_authresult: it.xxxxxxx..local\paloaltovpntest authresult auth'ed&lt;BR /&gt;2016-08-03 13:24:56.126 +0200 Request received to unlock vsys1/LDAP_USER_VPN_FR-1-1/it.xxxxxx.local\paloaltovpntest&lt;BR /&gt;2016-08-03 13:24:56.131 +0200 User 'it.xxxxxxx.local\paloaltovpntest' authenticated. From: 85..x.x.x&lt;/P&gt;</description>
      <pubDate>Thu, 11 Aug 2016 07:48:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101107#M44385</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-08-11T07:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect authentication LDAP not working fine</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101112#M44386</link>
      <description>&lt;P&gt;I'm sure the answer is yes but just to be sure, there is the allow list on the Authentification Profile and the actual GlobalProtect Portals, is the user group allowed on both of these?&lt;/P&gt;&lt;P&gt;*As a side note their is a known issue on older versions of the software where authentification issues would take place if the firewall was running for more than a 1 year time period without being shutdown. I would start with seeing if that fixes your issues if you are in an enviroment where you can schedule a restart in a resonable amount of time. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 13:38:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101112#M44386</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-03T13:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect authentication LDAP not working fine</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101117#M44389</link>
      <description>&lt;P&gt;Yes, the users are on this allowed group. When we commit it, its working but 2-3 hours later not &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Uptime 188 days, 13:37:57. Itos not very long this uptime right??? is there any bug id for this??&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 13:43:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101117#M44389</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-08-03T13:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect authentication LDAP not working fine</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101171#M44403</link>
      <description>&lt;P&gt;Any idea???&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 09:21:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101171#M44403</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-08-04T09:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect authentication LDAP not working fine</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101189#M44408</link>
      <description>&lt;P&gt;Looks like a possible typo in the domain field&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;'&lt;SPAN&gt;it.xxxxxxx..local\paloaltovpntest'&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;xxx..local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;should this be .local? Or just it.xxxx\paloaltovpntest , removing the .local?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ben&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 10:59:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101189#M44408</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-08-04T10:59:34Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect authentication LDAP not working fine</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101190#M44409</link>
      <description>&lt;P&gt;I think the config is OK because thisis working fine but 2-3 hours later stop authenticating.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Doing a debug we see this event and after stops authenticating fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2016-08-03 12:18:46.906 +0200 debug: authd_sysd_groupinfosync_callback(pan_authd.c:4349): will update vsys1, cn=ggfrpaloaltorasvpn,ou=_generic_groups,dc=fr,dc=xxxxxxxxx,dc=local here using file /opt/pancfg/mgmt/global/groups/1/Y249Z2dmcnBhbG9hbHRvcmFzdnBuLG91PV9nZW5lcmljX2dyb3VwcyxkYz1mcixkYz1zZWN1cml0YXNkaXJlY3QsZGM9bG9jYWw=.xml&lt;/P&gt;&lt;P&gt;2016-08-03 12:18:51.509 +0200 debug: authd_sysd_groupinfosync_callback(pan_authd.c:4363): done updating vsys1, cn=ggfrpaloaltorasvpn,ou=_generic_groups,dc=fr,dc=xxxxxxxxx,dc=local here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its like after doing the refresh stop working but nothing was changed in LDAP or PA.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 11:06:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-authentication-ldap-not-working-fine/m-p/101190#M44409</guid>
      <dc:creator>soporteseguridad</dc:creator>
      <dc:date>2016-08-04T11:06:10Z</dc:date>
    </item>
  </channel>
</rss>

