<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication seems to be the most difficult task.... in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/181262#M56000</link>
    <description>&lt;P&gt;ok sorry i've lost the thread here slightly...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in my authentication profile I have the following settings&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;user domain ( our domain name)&lt;/P&gt;&lt;P&gt;username modifier&amp;nbsp; (%USERINPUT%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is this similar to yours.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Oct 2017 11:28:42 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-10-11T11:28:42Z</dc:date>
    <item>
      <title>Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180538#M55874</link>
      <description>&lt;P&gt;No matter how many articles I read or follow I can never get the authentication to work for LDAP. I create the LDAP server profile, create the Auth Profile, then the Auth Seq, add the user account to admins and assign the profile to that user and it never works. I also get this error when "testing":&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt; test authentication authentication-profile Palo_Alto_Admins username Steven.Williams.da password&lt;BR /&gt;Enter password :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Allow list check error:&lt;BR /&gt;Target vsys is not specified, user "Steven.Williams.da" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;User Steven.Williams.da is not allowed with authentication profile Palo_Alto_Admins&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dmin@TN-19023-PA500-01&amp;gt; show user group-mapping state all&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Group Mapping(vsys1, type: active-directory): Network_Administrators&lt;BR /&gt;Bind DN : ldap.read@domain.lan&lt;BR /&gt;Base : DC=domain,DC=lan&lt;BR /&gt;Group Filter: (None)&lt;BR /&gt;User Filter: (None)&lt;BR /&gt;Servers : configured 4 servers&lt;BR /&gt;10.100.6.205(636)&lt;BR /&gt;Last Action Time: 19 secs ago(took 0 secs)&lt;BR /&gt;Next Action Time: In 41 secs&lt;BR /&gt;10.100.6.210(636)&lt;BR /&gt;10.100.21.210(636)&lt;BR /&gt;10.110.6.210(636)&lt;BR /&gt;Number of Groups: 1&lt;BR /&gt;cn=paloaltoadmins,ou=groups,ou=domain,dc=domain,dc=lan&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AD group.PNG" style="width: 533px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11780i496DFAC0A1D1E701/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AD group.PNG" alt="AD group.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Auth_Profile.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11779iF0739384A4948CB5/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Auth_Profile.PNG" alt="Auth_Profile.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="seq.PNG" style="width: 597px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11781i70098C5A1739C890/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="seq.PNG" alt="seq.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Oct 2017 13:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180538#M55874</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-06T13:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180801#M55909</link>
      <description>&lt;P&gt;show user group name "cn=paloaltoadmins,ou=groups,ou=domain,dc=domain,dc=lan"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you see group members?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 10:21:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180801#M55909</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T10:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180865#M55924</link>
      <description>&lt;P&gt;Matching the syntax of your accounts and groups is crucial for LDAP requests. &amp;nbsp;You can find the proper synatax for your user or group by using the "Distinguished Name" field in "Active Directory Users and Computers".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Open up&amp;nbsp;&lt;SPAN&gt;"Active Directory Users and Computers" and right click on your root domain. &amp;nbsp;Choose the "Find" option from the pop-up menu. &amp;nbsp;From the drop-down menu "View" select "Choose Columns" and then add the column for "Distinguished Name".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Search for your account. &amp;nbsp;In this example we have a user with the word Palo in the name. &amp;nbsp;The search box will show you the syntax for an LDAP query (example: CN=xxxxxx, OU=yyyyyy, DC=com). &amp;nbsp;This will have your specific information required for the Palo Alto.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LDAP-Info.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11850i0BA8A294DBA722F9/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LDAP-Info.png" alt="LDAP-Info.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 16:28:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180865#M55924</guid>
      <dc:creator>davanderson</dc:creator>
      <dc:date>2017-10-09T16:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180874#M55926</link>
      <description>&lt;P&gt;That command returns nothing. So I assume it cant see it?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 16:51:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180874#M55926</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T16:51:07Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180876#M55927</link>
      <description>&lt;P&gt;if the PA cannot see it then it will not allow you to even try to auth, could be a number of things but for basics I would try:-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this is just to make sure you have the correct group name in the first place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then try to remove admins from the auth profile, open it up to "any" and redo the "test authentication authentication-profile" again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also... to avoid vsys error....&amp;nbsp;&amp;nbsp;&amp;nbsp; set system setting target-vsys vsys1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 17:01:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180876#M55927</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T17:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180891#M55929</link>
      <description>&lt;P&gt;sorry the show user group list may not help... as groups available was in your first post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it may be that the bind account does not have enough permissions to see the users in the group, just the group lists.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 17:12:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180891#M55929</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T17:12:44Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180893#M55930</link>
      <description>&lt;P&gt;The show user group list only shows the user/groups in the Group Mapping Settings which from what I am reading this is not needed when doing WEB GUI auth.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also that command you mention doesnt exist:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA500-01&amp;gt; set system setting&lt;BR /&gt;&amp;gt; ctd ctd&lt;BR /&gt;&amp;gt; logging logging&lt;BR /&gt;&amp;gt; mp-memory-monitor Set monitoring of management memory&lt;BR /&gt;&amp;gt; packet packet&lt;BR /&gt;&amp;gt; packet-descriptor-monitor Set monitoring of packet descriptors&lt;BR /&gt;&amp;gt; pow pow&lt;BR /&gt;&amp;gt; shared-policy Shared policy management via Panorama&lt;BR /&gt;&amp;gt; ssl-decrypt ssl-decrypt&lt;BR /&gt;&amp;gt; template Template management via Panorama&lt;BR /&gt;&amp;gt; url-database URL database&lt;BR /&gt;&amp;gt; url-filtering-feature change URL filtering feature settings&lt;BR /&gt;&amp;gt; util util&lt;BR /&gt;&amp;gt; wildfire wildfire settings&lt;BR /&gt;&amp;gt; zip zip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 17:22:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180893#M55930</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T17:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180894#M55931</link>
      <description>&lt;P&gt;sorry... busy day...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also ensure bind account in ldap profile is at least a member of server operators group in AD.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 17:25:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180894#M55931</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T17:25:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180897#M55932</link>
      <description>&lt;P&gt;Well if I set the authentication profile to "all users" it works just fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enter password :&lt;/P&gt;&lt;P&gt;Target vsys is not specified, user "steven.williams.da" is assumed to be configured with a shared auth profile.&lt;/P&gt;&lt;P&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;name "domain.lan\steven.williams.da" is in group "all"&lt;/P&gt;&lt;P&gt;Authentication to LDAP server at 10.100.21.210 for user "steven.williams.da"&lt;BR /&gt;Egress: 10.100.20.20&lt;BR /&gt;Type of authentication: GSSAPI&lt;BR /&gt;Starting LDAPS connection...&lt;BR /&gt;Succeeded to create a session with LDAP server&lt;BR /&gt;DN sent to LDAP server: CN=Steven Williams.da,OU=Users,OU=NoPoliciesApplied,OU=Users,OU=domain,DC=domain,DC=lan&lt;BR /&gt;User expires in days: never&lt;/P&gt;&lt;P&gt;Authentication succeeded for user "steven.williams.da"&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the Bind account is working, its just not working for a specific user group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt; show user group name cn=paloaltoadmins,ou=groups,ou=domain,dc=domain,dc=lan&lt;/P&gt;&lt;P&gt;short name: domain\paloaltoadmins&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: Domain_Users_and_Groups&lt;/P&gt;&lt;P&gt;[1 ] domain\steven.williams.da&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sees the user but can never auth with it. And yes I have created a user account in the local admins to match this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 18:25:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180897#M55932</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T18:25:51Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180902#M55933</link>
      <description>&lt;P&gt;Could you post auth profile and advaced.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 18:41:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180902#M55933</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T18:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180905#M55934</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AuthProfile.PNG" style="width: 607px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11851i19C5C1D0D05B8EE8/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AuthProfile.PNG" alt="AuthProfile.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AuthProfile1.PNG" style="width: 603px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11852i054A6BFBD6283B0C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AuthProfile1.PNG" alt="AuthProfile1.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 18:47:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180905#M55934</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T18:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180921#M55936</link>
      <description>&lt;P&gt;Looks fine, not sure why you are not using group mapping in user-id.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the pa will not do a dynamic lookup for group membership. It checks every 20 mins or so via group mapping and caches/updates locally.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;this maybe why you cannot see yourself in show user group name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try user-id group mapping, scroll to your group and add it to the list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"debug user-id refresh group-mapping all". &amp;nbsp;Will auto update or wait 20 mins.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then try show user group name again to see if you are seen in your group.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:01:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180921#M55936</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T19:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180923#M55937</link>
      <description>&lt;P&gt;Already there:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AuthProfile2.PNG" style="width: 712px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11854i57BAE003C1F8C88D/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="AuthProfile2.PNG" alt="AuthProfile2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:04:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180923#M55937</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T19:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180924#M55938</link>
      <description>&lt;P&gt;Ok so what do you get if you do a show user group name for the domain admins group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;post if poss. Doesn't help but just curious.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:06:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180924#M55938</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T19:06:44Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180926#M55939</link>
      <description>&lt;P&gt;lost me. What group?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:09:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180926#M55939</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T19:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180927#M55940</link>
      <description>&lt;P&gt;Do..... &amp;nbsp; Show user group list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and post result.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:13:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180927#M55940</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T19:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180928#M55941</link>
      <description>&lt;P&gt;admin@PA500-01&amp;gt; show user group list&lt;/P&gt;&lt;P&gt;cn=paloaltoadmins,ou=groups,ou=domain,dc=domain,dc=lan&lt;BR /&gt;cn=domain users,cn=users,dc=domain,dc=lan&lt;/P&gt;&lt;P&gt;Total: 2&lt;BR /&gt;* : Custom Group&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:14:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180928#M55941</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T19:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180929#M55942</link>
      <description>&lt;P&gt;sorry users not admins...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group name "cn=domain users,cn=users,dc=domain,dc=lan"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just to see if the members are seen by the pa.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180929#M55942</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T19:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180930#M55943</link>
      <description>&lt;P&gt;admin@PA500-01&amp;gt; show user group name "cn=domain users,cn=users,dc=domain,dc=lan" | match steven.williams&lt;BR /&gt;[5510 ] domain\steven.williams&lt;BR /&gt;[5515 ] domain\steven.williams.da&lt;BR /&gt;admin@PA500-01&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I sure am.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This one too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt; show user group name "cn=paloaltoadmins,ou=groups,ou=domain,dc=domain,dc=lan"&lt;/P&gt;&lt;P&gt;short name: domain\paloaltoadmins&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: Domain_Users_and_Groups&lt;/P&gt;&lt;P&gt;[1 ] domain\steven.williams.da&lt;/P&gt;&lt;P&gt;admin@PA500-01&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Something just isn't making sense.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180930#M55943</guid>
      <dc:creator>s.williams1</dc:creator>
      <dc:date>2017-10-09T19:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication seems to be the most difficult task....</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180931#M55944</link>
      <description>&lt;P&gt;Not making sense... Welcome to my world of re badged junipers, sorry i meant palo altos....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in the server profile try removing the authentication modifier, or set to none, cant remember the exact setting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also.. Yo did say in your first reply that show user group came back with no results. Cant see why it does now...&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2017 19:31:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-seems-to-be-the-most-difficult-task/m-p/180931#M55944</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-10-09T19:31:01Z</dc:date>
    </item>
  </channel>
</rss>

