<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory Authentication for GlobalProtect issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161331#M52497</link>
    <description>&lt;P&gt;Use Authentication Sequence profile instead of separate local and LDAP logins, and remove the user domain from the group mapping &amp;amp; auth profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2017 06:48:26 GMT</pubDate>
    <dc:creator>MohamedSharief</dc:creator>
    <dc:date>2017-06-15T06:48:26Z</dc:date>
    <item>
      <title>Active Directory Authentication for GlobalProtect issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161181#M52463</link>
      <description>&lt;P&gt;Hi !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, I am using GlobalProtect in my network.&lt;/P&gt;&lt;P&gt;Also, I am configuring an Active Directory Server, and I would like to use AD users to connect to GlobalProtect (currently I'm&amp;nbsp;using local users / groups in the firewall). Computers are not in the domain yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have followed this tutorial :&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Active-Directory-Server-Profile-for-Group/ta-p/58089" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Active-Directory-Server-Profile-for-Group/ta-p/58089&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I verify connection to the LDAP server (with command: &lt;EM&gt;show user group name domain\usersgroup1&lt;/EM&gt;), I've all my users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I try to connect to GlobalProtect with an AD user, it's doesn't work and I have this error message in System logs: Authentification failed : Invalid username or password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you got any idea to solve the problem ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all !&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is details of my configuration :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LDAP Server Profile:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Server LDAP.PNG" style="width: 622px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9708i0231640DB56A1129/image-dimensions/622x331/is-moderation-mode/true?v=v2" width="622" height="331" role="button" title="Server LDAP.PNG" alt="Server LDAP.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Group Mapping:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Group Mapping 1.PNG" style="width: 465px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9709iF2BBDFEBB884CBCB/image-dimensions/465x475/is-moderation-mode/true?v=v2" width="465" height="475" role="button" title="Group Mapping 1.PNG" alt="Group Mapping 1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Group Mapping 2.PNG" style="width: 443px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9710iD3758DCCBE011FBD/image-dimensions/443x294/is-moderation-mode/true?v=v2" width="443" height="294" role="button" title="Group Mapping 2.PNG" alt="Group Mapping 2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is my Authentification profile :&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Auth Profile.PNG" style="width: 426px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9711iA4BD6C132511E976/image-dimensions/426x294/is-moderation-mode/true?v=v2" width="426" height="294" role="button" title="Auth Profile.PNG" alt="Auth Profile.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Auth Profile 2.PNG" style="width: 489px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9713i058879DEAAD9525C/image-dimensions/489x413/is-moderation-mode/true?v=v2" width="489" height="413" role="button" title="Auth Profile 2.PNG" alt="Auth Profile 2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;And this is the GlobalProtect Authentication configuration:&lt;/P&gt;&lt;P&gt;Portal :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Portal Auth.PNG" style="width: 512px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9714iFD1C26058C313CB1/image-dimensions/512x305/is-moderation-mode/true?v=v2" width="512" height="305" role="button" title="Portal Auth.PNG" alt="Portal Auth.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Portal Auth 2.PNG" style="width: 510px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9715i7B8119FBFE153EED/image-dimensions/510x263/is-moderation-mode/true?v=v2" width="510" height="263" role="button" title="Portal Auth 2.PNG" alt="Portal Auth 2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Gateway :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="passerelle auth.PNG" style="width: 549px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/9716i520E317CB0E2E10D/image-dimensions/549x323/is-moderation-mode/true?v=v2" width="549" height="323" role="button" title="passerelle auth.PNG" alt="passerelle auth.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 10:29:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161181#M52463</guid>
      <dc:creator>informatiq</dc:creator>
      <dc:date>2017-06-14T10:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication for GlobalProtect issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161306#M52489</link>
      <description>&lt;P&gt;Very well documented post!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) If you are entering the domain yourself, under Authentication profile-&amp;gt;User domain, then put the user modifier as %username% only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) If step (1) doesn't work, then run:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; tail follow yes mp-log authd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then try to authenticate. Copy and paste those logs here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good Luck!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 22:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161306#M52489</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-06-14T22:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication for GlobalProtect issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161311#M52494</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58639"&gt;@informatiq&lt;/a&gt;&lt;/P&gt;&lt;P&gt;In the &lt;STRONG&gt;Group Mapping --&amp;gt; Domain Setting --&amp;gt; User Domain&lt;/STRONG&gt;, include only your NetBios name or leave it blank, for instance: in your example it is &lt;STRONG&gt;domain.ad&lt;/STRONG&gt;, so leave it as &lt;STRONG&gt;domain&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the Authentication Profile User Domain field, either remove it completely or also include only your NetBios.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both actions should resolve this issue for you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Willian&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 22:52:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161311#M52494</guid>
      <dc:creator>acc6d0b3610eec313831f7900fdbd235</dc:creator>
      <dc:date>2017-06-14T22:52:27Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory Authentication for GlobalProtect issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161331#M52497</link>
      <description>&lt;P&gt;Use Authentication Sequence profile instead of separate local and LDAP logins, and remove the user domain from the group mapping &amp;amp; auth profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sharief&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 06:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-authentication-for-globalprotect-issue/m-p/161331#M52497</guid>
      <dc:creator>MohamedSharief</dc:creator>
      <dc:date>2017-06-15T06:48:26Z</dc:date>
    </item>
  </channel>
</rss>

