<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NTLM authentication problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166778#M53387</link>
    <description>&lt;P&gt;You can find the screenshot:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NTLM.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10432i01EDEBE5A4A5A991/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NTLM.PNG" alt="NTLM.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Jul 2017 14:14:51 GMT</pubDate>
    <dc:creator>niitnn</dc:creator>
    <dc:date>2017-07-17T14:14:51Z</dc:date>
    <item>
      <title>NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166743#M53380</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I`m trying to configure NTLM Authentification over Captive Portal for users in my network. I have PA-500. I set the next configuration parameters:&lt;/P&gt;&lt;P&gt;1. LDAP Server Profile&lt;/P&gt;&lt;P&gt;2. Authentication Profile&lt;/P&gt;&lt;P&gt;3. Authentication Policy (Authentication enforcement is "default-browser-challenge")&lt;/P&gt;&lt;P&gt;4. User-ID checkbox on the trust zone&lt;/P&gt;&lt;P&gt;5. Generate certificate and made SSL/TLS service Profile&lt;/P&gt;&lt;P&gt;6. Enable Captive Portal and NTLM Authentication with redirecting to IP-address of the trust zone Interface&lt;/P&gt;&lt;P&gt;7. Service Account included to Event Log Reader and Distributed COM groups and for this Account were delegated rights to join cmputers to domain.&lt;/P&gt;&lt;P&gt;8. In the ou=Computers was crteated Computer Account for my PA. Then Service account (by logs&amp;nbsp;on DC)&amp;nbsp;made some changes with that Computer Account&amp;nbsp;and then deleted that Computer Account automatically.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And now users enter site names to IE address string and redirect to web-form authentication. But even if user enters the wright password, web-form writes "Wrong username/password" message. In system logs there are messages "SSO NTLM Authentication failed". And no entries in User - IP table.&lt;/P&gt;&lt;P&gt;Installed PAN OS - 8.0.3-h4.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need agentless User-ID configuration with NTLM Authentification. What I'm doing wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 11:24:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166743#M53380</guid>
      <dc:creator>niitnn</dc:creator>
      <dc:date>2017-07-17T11:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166758#M53384</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66201"&gt;@niitnn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Is the failure strickly with IE? They made some changes that break this on IE11 unless you revert to how things were configured previously. The article below specifies what changes would have to be made.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Captive-Portal-NTLM-Authentication-Fails-With-IE11/ta-p/56024" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Captive-Portal-NTLM-Authentication-Fails-With-IE11/ta-p/56024&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 12:57:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166758#M53384</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-17T12:57:11Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166762#M53385</link>
      <description>&lt;P&gt;IE is the base browser in our organization. Therefor&amp;nbsp;I'm trying to connect to Internet exactly by IE. I saw thia article about IE11 a added Captive Portal redirect host to Intranet zone. But no effect...&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 13:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166762#M53385</guid>
      <dc:creator>niitnn</dc:creator>
      <dc:date>2017-07-17T13:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166770#M53386</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66201"&gt;@niitnn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Could you share a screenshot of your NTLM configuration. Also can you verify that you did&amp;nbsp;&lt;STRONG&gt;not&lt;/STRONG&gt; include the domain name within the Admin User section of the configuration.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 14:06:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166770#M53386</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-17T14:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166778#M53387</link>
      <description>&lt;P&gt;You can find the screenshot:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="NTLM.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10432i01EDEBE5A4A5A991/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="NTLM.PNG" alt="NTLM.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 14:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166778#M53387</guid>
      <dc:creator>niitnn</dc:creator>
      <dc:date>2017-07-17T14:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166839#M53393</link>
      <description>&lt;P&gt;I'm starting to wonder if the issue wasn't with the firewall removing itself from the computer OU that is causing you issues. You might want to disable NTLM comitt and then enable it again and see what happens.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you run 'show user server-monitor state all' on the firewall do you see any NTLM stats there?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jul 2017 18:34:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166839#M53393</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-17T18:34:53Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166949#M53404</link>
      <description>&lt;P&gt;It's wonder for me too. Disable NTLM - Commit - Enable NTLM - Commit takes no effect.&lt;/P&gt;&lt;P&gt;Logs from DC:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10446iFB21C2694200EB9D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA.PNG" alt="PA.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fnd the output from 'show user server-monitor state all':&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP Syslog Listener Service is disabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL Syslog Listener Service is disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May be I missed to set any parameter? Or this is a bug of PAN OS 8.0.3 ?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 07:30:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166949#M53404</guid>
      <dc:creator>niitnn</dc:creator>
      <dc:date>2017-07-18T07:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166992#M53409</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/66201"&gt;@niitnn&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;It could very well be a bug, it looks like you have everything configured correctly and your service account appears to be functioning perfectly fine. I would open a case with TAC if able so you can get their input.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 12:40:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166992#M53409</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-07-18T12:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: NTLM authentication problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166998#M53411</link>
      <description>&lt;P&gt;Thank you. But now the best way is downgrade to 7.0.17?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2017 12:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ntlm-authentication-problems/m-p/166998#M53411</guid>
      <dc:creator>niitnn</dc:creator>
      <dc:date>2017-07-18T12:51:45Z</dc:date>
    </item>
  </channel>
</rss>

