<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect users dont pass authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-users-dont-pass-authentication/m-p/208867#M61101</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you run the command as stated below, switching the info out with your group, does the firewall properly poll the group and display the requesting user?&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;show user group name cn=palo--lab-admin-users,ou=groups,ou=lab-enviroment,dc=lab,dc=root,dc=local&lt;/PRE&gt;</description>
    <pubDate>Thu, 05 Apr 2018 13:38:47 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2018-04-05T13:38:47Z</dc:date>
    <item>
      <title>Global protect users dont pass authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-users-dont-pass-authentication/m-p/208800#M61091</link>
      <description>&lt;P&gt;Hello all&lt;/P&gt;&lt;P&gt;we have PA in production.The problem is VPN users dont pass by certain authentication profile.The issue is that when we point user it is ok but when we point some group it fails to authenticate&lt;/P&gt;&lt;P&gt;we test through CLI and that is result&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;test authentication authentication-profile VPN_LDAP username eradmin password&lt;BR /&gt;Enter password :&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Allow list check error:&lt;BR /&gt;Target vsys is not specified, user "eradmin" is assumed to be configured with&lt;BR /&gt;a shared auth profile.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;Do allow list check before sending out authentication request...&lt;BR /&gt;User&amp;nbsp;eradmin is not allowed with authentication profile VPN_LDAP&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This eradmin user is the member of VPN-USERS group.When we point this user separately it is ok but inside the group it fail to authenticate&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Model is 820&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PAN OS- 8.0.7&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 20:08:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-users-dont-pass-authentication/m-p/208800#M61091</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-04-04T20:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect users dont pass authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-users-dont-pass-authentication/m-p/208867#M61101</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If you run the command as stated below, switching the info out with your group, does the firewall properly poll the group and display the requesting user?&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;show user group name cn=palo--lab-admin-users,ou=groups,ou=lab-enviroment,dc=lab,dc=root,dc=local&lt;/PRE&gt;</description>
      <pubDate>Thu, 05 Apr 2018 13:38:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-users-dont-pass-authentication/m-p/208867#M61101</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-04-05T13:38:47Z</dc:date>
    </item>
  </channel>
</rss>

