<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: authenticate with domain\username in Global Protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175558#M55001</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp; Thx a lot&amp;nbsp;&lt;/P&gt;&lt;P&gt;well, that is what i did ( i guess by Auth Order you means the Auth Sequence)&lt;/P&gt;&lt;P&gt;but my point is that on the Client Auth, you have the possibility to add several profile. Something i tested by adding several Profile But everytime only the first profil currently on the top of the list was being checked the other below was not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you said that worked quite well. i defined a new Auth Seq then i added all other Profile into it.&lt;/P&gt;&lt;P&gt;later added the newly created Auth Seq to GP.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Sep 2017 04:29:25 GMT</pubDate>
    <dc:creator>big_Gilo</dc:creator>
    <dc:date>2017-09-08T04:29:25Z</dc:date>
    <item>
      <title>authenticate with domain\username in Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175165#M54928</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have set the authentication Profile (username Modifier) to&amp;nbsp;%USERDOMAIN%\%USERINPUT%&lt;/P&gt;&lt;P&gt;because i want all user currently using GP to add thei domain as well not just the username.&lt;/P&gt;&lt;P&gt;the Profil has been added to the GP authentication section.&lt;/P&gt;&lt;P&gt;but everytime i just get failed authentication from these users.&lt;/P&gt;&lt;P&gt;but the second authentication profil is accepting only the&amp;nbsp;&lt;SPAN&gt;%USERINPUT% as input. Meaning all users on the second profil are able to authenticate without any problem.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;both Profile are using the same GP settings (configured on the same GP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;did i in my config miss anything ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i would deeply appreciate if someone could provide me with some hints.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;cheers,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Gilo&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 12:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175165#M54928</guid>
      <dc:creator>big_Gilo</dc:creator>
      <dc:date>2017-09-06T12:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate with domain\username in Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175173#M54929</link>
      <description>&lt;P&gt;Hi Gilo,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bit of a stab in the dark and maybe one of the others can help more however for a quick check/test:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you checked the logs on the DC to see what was being sent through from the Palo when it fails, i'm thinking maybe you have added a domain within the domain field (either within the LDAP profile or the Authentication profile depending which PAN-OS version you are using) which would append the domain entry,. Remove the domain entry and retest.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also you can tail the logs on the Palo to maybe gain some more insight, &amp;gt; tail follow yes mp-log authd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again this is a true stab in the dark and hopefully the others can provide additional assistance.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 13:18:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175173#M54929</guid>
      <dc:creator>Ben-W</dc:creator>
      <dc:date>2017-09-06T13:18:09Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate with domain\username in Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175328#M54956</link>
      <description>&lt;P&gt;using the %USERDOMAIN%\%USERINPUT% option will remove any "domain\" entered by the user and use the domain info in the "user domain" field of the authentication profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you do not have a "user domain" entry in the profile then the palo alto will attempt to resolve the domain name via group mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 07:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175328#M54956</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-07T07:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate with domain\username in Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175408#M54970</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5754"&gt;@Ben-W&lt;/a&gt;&amp;nbsp; thank you very much for the hints. your ideas really helped me out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have solved the Problem. what i had before was as follow:&amp;nbsp;&lt;/P&gt;&lt;P&gt;- on GP --&amp;gt; Client Auth, i had both Profile ( Auth Profil A und Auth Profil B)&lt;/P&gt;&lt;P&gt;1-Profil A= only with username&amp;nbsp;&lt;/P&gt;&lt;P&gt;2-Profil B= with domain and username &amp;nbsp;(here&amp;nbsp;i do not have a domain in the Uer Domain ( i removed it ) )&lt;/P&gt;&lt;P&gt;so every time the client on Profil B tried to sign in, GP only hit the 1st profil (Profil A)&lt;/P&gt;&lt;P&gt;user on A were able to log in without any problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, i just created one Authentication Sequence Profil X = A and B&lt;/P&gt;&lt;P&gt;and on GP &amp;nbsp;--&amp;gt; Client Auth i just added the Auth Seq X . Then I worked &amp;nbsp;as i wanted&amp;nbsp;&lt;/P&gt;&lt;P&gt;on the Auth Seq it checked the first Auth Profil does not get a hit then moves to the next Auth Profil.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;what i find a weird is taht why on GP --&amp;gt; Client Auth tab, you have the Option to add several Profil for authentication but instead of checking all the profil in that list it just hits the first Profil and does not check other profil.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 12:32:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175408#M54970</guid>
      <dc:creator>big_Gilo</dc:creator>
      <dc:date>2017-09-07T12:32:20Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate with domain\username in Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175409#M54971</link>
      <description>&lt;P&gt;for GP to check all authentication profiles you need to add them to an "authentication order" and then add the "authentication order" to the client auth tab.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 12:38:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175409#M54971</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-07T12:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate with domain\username in Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175558#M55001</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp; Thx a lot&amp;nbsp;&lt;/P&gt;&lt;P&gt;well, that is what i did ( i guess by Auth Order you means the Auth Sequence)&lt;/P&gt;&lt;P&gt;but my point is that on the Client Auth, you have the possibility to add several profile. Something i tested by adding several Profile But everytime only the first profil currently on the top of the list was being checked the other below was not.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you said that worked quite well. i defined a new Auth Seq then i added all other Profile into it.&lt;/P&gt;&lt;P&gt;later added the newly created Auth Seq to GP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 04:29:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175558#M55001</guid>
      <dc:creator>big_Gilo</dc:creator>
      <dc:date>2017-09-08T04:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: authenticate with domain\username in Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175579#M55010</link>
      <description>&lt;P&gt;sorry, yes "sequence"&lt;/P&gt;&lt;P&gt;the auth profile on the portal config has always been a gripe of mine. seems to work OK for different OS option but i was also never able to try all profiles for the same OS. i suppose this makes sense but the help file does suggest that you can have multiple auths profiles for the same OS.&lt;/P&gt;&lt;P&gt;It may work in the same way as the setup within Device\Authentication Profile. this will only try the next option if the auth server does not respond.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... now they have added "Authentication Sequence" all is good.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:33:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authenticate-with-domain-username-in-global-protect/m-p/175579#M55010</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-08T07:33:10Z</dc:date>
    </item>
  </channel>
</rss>

