<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to logon to the firewalls using the AD account in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251613#M71545</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;That's actually how it's suppose to work. The PAN-OS won't create the administrator account by itself, the authentication profile is simply used the authenticate administrator accounts that have already been created.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 28 Feb 2019 00:40:50 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2019-02-28T00:40:50Z</dc:date>
    <item>
      <title>Unable to logon to the firewalls using the AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251595#M71543</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setup LDAP authentication for login purposes, the server profile has been created along with the authentication profile, user group mapping (which searches for an AD group) and the administrator which uses the authentication profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However I am unable to logon to the firewalls using the AD account, when I check the system logs for the firewall I get the following message "Authentication profile not found for the user".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did an authentication test using the command "test authentication authentication-profile &amp;lt;profile&amp;gt; username &amp;lt;username&amp;gt; password" and it came back that the user was authenticated successfully, I can also see that the firewalls are correctly collecting the members of the AD group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I managed to get the LDAP authentication working, but not in the way I was hoping it would work. I can authenticate a user by making an administrator account for each individual AD user that I want to be able to login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was hoping there was a way to have it setup where an AD group can be used and members of that group can login to panorama without having to create individual administrator accounts for each. Not sure if that’s possible or not with Pan-OS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2019 23:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251595#M71543</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-02-27T23:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to logon to the firewalls using the AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251613#M71545</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;That's actually how it's suppose to work. The PAN-OS won't create the administrator account by itself, the authentication profile is simply used the authenticate administrator accounts that have already been created.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 00:40:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251613#M71545</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-28T00:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to logon to the firewalls using the AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251614#M71546</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So what do I need to do in the FW so that I don't get the message "Authentication profile not found for the user"?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 00:45:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251614#M71546</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-02-28T00:45:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to logon to the firewalls using the AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251616#M71548</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Create an administrator account for the user you are wishing to add to the firewall, when creating the entry ensure that the authentication profile for the account has your LDAP profile specified. If that's done you shouldn't get any errors in the log files.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 00:48:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251616#M71548</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-28T00:48:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to logon to the firewalls using the AD account</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251617#M71549</link>
      <description>&lt;P&gt;You can have an auth system where you don't need to continue adding admins to the firewall directly, but you have to use RADIUS for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The mechanism uses Vendor Specific Attributes (VSAs) that the firewall sees and assigns a role. Here's an article that shows the details for Panorama for Windows 2003, 2008, and Cisco ACS 4.0:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIxCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIxCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another for just firewalls, and specific to Windows 2008:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGMCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGMCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Feb 2019 00:50:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-logon-to-the-firewalls-using-the-ad-account/m-p/251617#M71549</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2019-02-28T00:50:54Z</dc:date>
    </item>
  </channel>
</rss>

