<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global protect AD strange issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271664#M74851</link>
    <description>&lt;P&gt;I have a strange and critical issue. I have Always-on type global protect with cert based username and OTP authentication method on handful of user machines. I have set the captive portal timeout for 0 and enforce network access under portal app settings.&lt;/P&gt;&lt;P&gt;these users each have 2 machines.whenever the user changes his AD password on a different machine, the one with globalprotect doesn't connect to the network and says the connection is unauthenticated. How does GP interfere with user AD creds? As I mentioned earlier, I am using firewall issued certificate and RADIUS based OTP authentication method.&lt;/P&gt;&lt;P&gt;TIA.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2019 12:43:40 GMT</pubDate>
    <dc:creator>SThatipelly</dc:creator>
    <dc:date>2019-06-20T12:43:40Z</dc:date>
    <item>
      <title>Global protect AD strange issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271664#M74851</link>
      <description>&lt;P&gt;I have a strange and critical issue. I have Always-on type global protect with cert based username and OTP authentication method on handful of user machines. I have set the captive portal timeout for 0 and enforce network access under portal app settings.&lt;/P&gt;&lt;P&gt;these users each have 2 machines.whenever the user changes his AD password on a different machine, the one with globalprotect doesn't connect to the network and says the connection is unauthenticated. How does GP interfere with user AD creds? As I mentioned earlier, I am using firewall issued certificate and RADIUS based OTP authentication method.&lt;/P&gt;&lt;P&gt;TIA.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 12:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271664#M74851</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-06-20T12:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect AD strange issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271729#M74855</link>
      <description>&lt;P&gt;Although you are not using SSO, you could set "Use single sign-on (windows only)" to "No" in your portal app config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;may seem a bit random but it has caused me issues in the past.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 15:14:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271729#M74855</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-06-20T15:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect AD strange issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271763#M74861</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp; thank you so much for the suggestion. I am going to try it now. Did this fix your issue?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 16:14:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271763#M74861</guid>
      <dc:creator>SThatipelly</dc:creator>
      <dc:date>2019-06-20T16:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect AD strange issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271770#M74863</link>
      <description>&lt;P&gt;it did fix my issue but for a different reason.&lt;/P&gt;&lt;P&gt;after a version update the authentication overide was not working correctly and in the system log on the firewall i could see the AD username failing OTP. the username for the OTP was different to the AD account so thats what gave it away..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only offer it as a suggestion as this is the only setting I know regarding AD auth...&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2019 16:23:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ad-strange-issue/m-p/271770#M74863</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-06-20T16:23:56Z</dc:date>
    </item>
  </channel>
</rss>

