<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Reason: User is not in allowlist in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/reason-user-is-not-in-allowlist/m-p/177903#M55431</link>
    <description>&lt;P&gt;&lt;SPAN&gt;User 'steven.williams.da' failed authentication. Reason: User is not in allowlist From: ltdlqq6h2.domain.lan&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;short name: domain\paloaltoadmins&lt;BR /&gt;source type: ldap&lt;BR /&gt;source: Network_Administrators&lt;/P&gt;&lt;P&gt;[1 ] domain\steven.williams.da&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication profile contains the user group paloaltoadmins using the LDAP server profile. Created user in local admin and addigned it the authetication profile. Still errors. Where can you get more details within a log for this, there has to be something deeper than this generic error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Sep 2017 17:50:11 GMT</pubDate>
    <dc:creator>s.williams1</dc:creator>
    <dc:date>2017-09-20T17:50:11Z</dc:date>
    <item>
      <title>Reason: User is not in allowlist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reason-user-is-not-in-allowlist/m-p/177903#M55431</link>
      <description>&lt;P&gt;&lt;SPAN&gt;User 'steven.williams.da' failed authentication. Reason: User is not in allowlist From: ltdlqq6h2.domain.lan&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;short name: domain\paloaltoadmins&lt;BR /&gt;source type: ldap&lt;BR /&gt;source: Network_Administrators&lt;/P&gt;&lt;P&gt;[1 ] domain\steven.williams.da&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Authentication profile contains the user group paloaltoadmins using the LDAP server profile. Created user in local admin and addigned it the authetication profile. Still errors. Where can you get more details within a log for this, there has to be something deeper than this generic error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Sep 2017 17:50:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reason-user-is-not-in-allowlist/m-p/177903#M55431</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-09-20T17:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: Reason: User is not in allowlist</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/reason-user-is-not-in-allowlist/m-p/178015#M55450</link>
      <description>&lt;P&gt;So you have group&amp;nbsp;&lt;SPAN&gt;domain\paloaltoadmins in your domain?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can use command below to check what Palo thinks in which AD group user is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe you need to edit&amp;nbsp;Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; Group Include List&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; show user user-ids match-user&amp;nbsp;&lt;SPAN&gt;steven.williams.da&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Sep 2017 05:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/reason-user-is-not-in-allowlist/m-p/178015#M55450</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-21T05:01:05Z</dc:date>
    </item>
  </channel>
</rss>

