<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RADIUS (not Active Directory) and Allow List in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9659#M7077</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello A.Cardaso,&lt;/P&gt;&lt;P&gt;You will always need to add the users to the allow list in the authentication profile if you are not going to user the local database. The authentication profile defines what users/groups will be allowed to connect over the VPN and how they will be authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned the following:&lt;/P&gt;&lt;P&gt;If I've to add users in Palo ALto then I don't need Radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you add users to the allow list, these are actually users that are already in active directory. Those users' credentials still need to be submitted to the radius server for verification. That is the significant difference between using local data base and radius.&lt;/P&gt;&lt;P&gt;Currently there isn't a mechanism on the Paloalto device to automatically add all of the AD users to the all list in the ssl vpn authentication profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Mar 2010 19:17:37 GMT</pubDate>
    <dc:creator>swhyte</dc:creator>
    <dc:date>2010-03-09T19:17:37Z</dc:date>
    <item>
      <title>RADIUS (not Active Directory) and Allow List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9657#M7075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I'm configuring a RADIUS different than Active Directory, I use Radius users for SSL-VPN and GUI and all works fine but always I've to add manually the Radius user to Allow List in Authentication Profile, is there any way to avoid this. If I've to add users in Palo ALto then I don't need Radius.&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2010 17:40:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9657#M7075</guid>
      <dc:creator>a.cadarso</dc:creator>
      <dc:date>2010-03-09T17:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS (not Active Directory) and Allow List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9658#M7076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isnt it possible to select "known-user" as with source user and policies?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2010 18:24:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9658#M7076</guid>
      <dc:creator>rps</dc:creator>
      <dc:date>2010-03-09T18:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS (not Active Directory) and Allow List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9659#M7077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello A.Cardaso,&lt;/P&gt;&lt;P&gt;You will always need to add the users to the allow list in the authentication profile if you are not going to user the local database. The authentication profile defines what users/groups will be allowed to connect over the VPN and how they will be authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned the following:&lt;/P&gt;&lt;P&gt;If I've to add users in Palo ALto then I don't need Radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you add users to the allow list, these are actually users that are already in active directory. Those users' credentials still need to be submitted to the radius server for verification. That is the significant difference between using local data base and radius.&lt;/P&gt;&lt;P&gt;Currently there isn't a mechanism on the Paloalto device to automatically add all of the AD users to the all list in the ssl vpn authentication profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Mar 2010 19:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9659#M7077</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-09T19:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS (not Active Directory) and Allow List</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9660#M7078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Samuel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try adding the magic word "all" (without the double quotes) in your Authentication Profile -&amp;gt; Edit Allow List -&amp;gt; Additional Users : "all"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It should work if you run 3.1.x, and hit commit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arnaud.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 May 2010 22:21:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-not-active-directory-and-allow-list/m-p/9660#M7078</guid>
      <dc:creator>akopp</dc:creator>
      <dc:date>2010-05-31T22:21:54Z</dc:date>
    </item>
  </channel>
</rss>

