<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP and user authentication/authorization in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7427#M5516</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Bind DN example, "CN=ldap,CN=users,DC=plano2003,DC=com", I'm a little confuse what to replace for CN=ldap and CN=users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;CN=ldap (should I replace with the OU of my Active Directory?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;CN=users (should I replace with the username?)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 13 Jun 2012 18:04:50 GMT</pubDate>
    <dc:creator>vnguyen2</dc:creator>
    <dc:date>2012-06-13T18:04:50Z</dc:date>
    <item>
      <title>LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7420#M5509</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;I have a problem using LDAP for user/management authentication/authorization. When I try to log in via my domain I get the following in my log (after logging in again with the admin account):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; font-size: 12pt; mso-ansi-language: EN-US; mso-fareast-language: NO-BOK;"&gt;Authorization failed for user *\*via Web from *.*.*.* : Invalid user 06/06 12:41:19&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-US" style="font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; font-size: 12pt; mso-ansi-language: EN-US; mso-fareast-language: NO-BOK;"&gt;User '*\*' authenticated. Profile authProfileAdmins in an authentication sequence AuthSeqDomainAdmins succeeded. &lt;/SPAN&gt;&lt;SPAN style="font-family: &amp;amp;quot;Times New Roman&amp;amp;quot;,&amp;amp;quot;serif&amp;amp;quot;; font-size: 12pt; mso-fareast-language: NO-BOK;"&gt;From: *.*.*.*.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Jun 2012 12:27:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7420#M5509</guid>
      <dc:creator>kaare_tragethon</dc:creator>
      <dc:date>2012-06-06T12:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7421#M5510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check the authentication profile and Authentication sequence. Are you referring to the correct profile for authentication. The empty spaces indicate that it is having trouble with the authentication profile &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2012 17:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7421#M5510</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2012-06-11T17:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7422#M5511</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi and thanks for the reply. Please see attached pictures of my current&lt;/P&gt;&lt;P&gt;setup. The LDAP has contact with the server, so this is not the problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards/Vennlig Hilsen,&lt;/P&gt;&lt;P&gt;Kåre Tragethon&lt;/P&gt;&lt;P&gt;IT &amp;amp; Automasjon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hallingplast AS&lt;/P&gt;&lt;P&gt;Tlf: +47 32 09 56 85&lt;/P&gt;&lt;P&gt;Fax: +47 32 09 55 94&lt;/P&gt;&lt;P&gt;Mob: +47 95 25 14 38&lt;/P&gt;&lt;P&gt;www.hallingplast.no&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 07:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7422#M5511</guid>
      <dc:creator>kaare_tragethon</dc:creator>
      <dc:date>2012-06-12T07:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7423#M5512</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could it be the classical mistake of using "domain.local" instead of just the netbios name "domain"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Described in &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://live.paloaltonetworks.com/thread/5050?tstart=0"&gt;https://live.paloaltonetworks.com/thread/5050?tstart=0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 09:27:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7423#M5512</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-12T09:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7424#M5513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks but that didn't help. By the way, I'm only using LDAP (no user&lt;/P&gt;&lt;P&gt;agent)..... I could also mention that I'm only trying to access the&lt;/P&gt;&lt;P&gt;Management Interface at the moment. Could that be a problem?? Do I have to&lt;/P&gt;&lt;P&gt;create any security rules to allow access?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 10:31:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7424#M5513</guid>
      <dc:creator>kaare_tragethon</dc:creator>
      <dc:date>2012-06-12T10:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7425#M5514</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I dont know if you can setup security rules for the management interface (if you use the physical mgmt int) - however you would need to do so if you have service rerouted your traffic to use a dataplane interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 06:25:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7425#M5514</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-13T06:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7426#M5515</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please follow the configuration steps provided in the following document: &lt;A class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1989"&gt;https://live.paloaltonetworks.com/docs/DOC-1989&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless the username you are using to login is 'AllowDomainAdmins', there is a misconfiguration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As outlined in the document, it is required to create a Device -&amp;gt; Administrator account for each AD account that will be used. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 16:44:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7426#M5515</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-06-13T16:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7427#M5516</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Bind DN example, "CN=ldap,CN=users,DC=plano2003,DC=com", I'm a little confuse what to replace for CN=ldap and CN=users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;CN=ldap (should I replace with the OU of my Active Directory?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;CN=users (should I replace with the username?)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 18:04:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7427#M5516</guid>
      <dc:creator>vnguyen2</dc:creator>
      <dc:date>2012-06-13T18:04:50Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7428#M5517</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the Bind DN example, a user named 'ldap' has been created inside of the 'CN=users,DC=plano2003,DC=com' container.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another example of this is if you were to use the built-in 'Administrator' account. The equivalent would be:&lt;/P&gt;&lt;P&gt;CN=administator,CN=users,DC=plano2003,DC=com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please know, a more simple way to specifiy the Bind DN is set username@domain. Here are some examples showing two different DN formats that are equivalent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CN=paloalto,OU=firewalls,OU=network,DC=plano2003,DC=com&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:paloalto@plano2003.com"&gt;paloalto@plano2003.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CN=ldap,CN=users,DC=plano2003,DC=com&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:ldap@plano2003.com"&gt;ldap@plano2003.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CN=administator,CN=users,DC=plano2003,DC=com&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:administrator@plano2003.com"&gt;administrator@plano2003.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is example screenshot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 19:02:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7428#M5517</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-06-13T19:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and user authentication/authorization</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7429#M5518</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The document is based on:&lt;/P&gt;&lt;P&gt;Root OU being&amp;nbsp; Plano.2003.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;EM&gt;ldap&lt;/EM&gt;&lt;/STRONG&gt; is contained in &lt;STRONG style="font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;EM&gt;Users&lt;/EM&gt;&lt;/STRONG&gt;, under &lt;STRONG style="font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;EM&gt;Plano.2003.com&lt;/EM&gt;&lt;/STRONG&gt;. The corresponding Bind DN is going to be &lt;EM style="font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;CN=ldap,CN=Users,DC=example,DC=com.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Please refer to the &lt;A class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2910"&gt;https://live.paloaltonetworks.com/docs/DOC-2910&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px;"&gt;Also try authentication removing the filtered Allow List.Most probably the user in question is not authorized the query the OU.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #ffffff; font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px;"&gt;Ameya&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: Arial, 'Lucida Grande', Geneva, Verdana, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 19:13:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-user-authentication-authorization/m-p/7429#M5518</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-06-13T19:13:02Z</dc:date>
    </item>
  </channel>
</rss>

