<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP Authentication Profile allow list 'all' in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298841#M78272</link>
    <description>&lt;P&gt;Thanks. And to clarify if a user isn't defined as an Administrator or as a Captive Portal or GlobalProtect user either explicitly or as a group member, then authentication will fail with something like an "Authentication profile not found for the user" message in the system log? Simply selecting 'all' in the allow list does not grant everyone the ability to login to the firewall, correct?&lt;/P&gt;</description>
    <pubDate>Fri, 15 Nov 2019 16:25:50 GMT</pubDate>
    <dc:creator>MikeSangray2019</dc:creator>
    <dc:date>2019-11-15T16:25:50Z</dc:date>
    <item>
      <title>LDAP Authentication Profile allow list 'all'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298624#M78232</link>
      <description>&lt;P&gt;When configuring an LDAP Authentication Profile what does the 'all' refer to in the allow list?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 18:30:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298624#M78232</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2019-11-14T18:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Profile allow list 'all'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298667#M78236</link>
      <description>&lt;P&gt;All is a reference to any user.&lt;/P&gt;&lt;P&gt;if you only wanted members of a certain group or individual users &amp;nbsp;to use this authentication profile then you would add them here.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 19:48:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298667#M78236</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-14T19:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Profile allow list 'all'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298841#M78272</link>
      <description>&lt;P&gt;Thanks. And to clarify if a user isn't defined as an Administrator or as a Captive Portal or GlobalProtect user either explicitly or as a group member, then authentication will fail with something like an "Authentication profile not found for the user" message in the system log? Simply selecting 'all' in the allow list does not grant everyone the ability to login to the firewall, correct?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 16:25:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298841#M78272</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2019-11-15T16:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Profile allow list 'all'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298857#M78274</link>
      <description>&lt;P&gt;Yes&amp;nbsp; I think so...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only say "think so" as i have never used any other option than "ALL". so i dont know what the system log would say...&amp;nbsp; but i'm sure you have already seen this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To allow all only means that all users can attempt to authenticate against this profile...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 16:39:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298857#M78274</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-15T16:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Profile allow list 'all'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298860#M78275</link>
      <description>&lt;P&gt;ok just tested the auth with a test profile without me in the allow list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;system log&amp;nbsp; &amp;nbsp;...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;failed authentication for user "Me" Reason: user is not in allow list. auth profile Radius Test.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Boom!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 16:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298860#M78275</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-15T16:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Authentication Profile allow list 'all'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298884#M78283</link>
      <description>&lt;P&gt;I did a similar test and got a similar result.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AFAIK setting the allow list to 'all' and relying on authentication profiles is the cleanest way to go about provisioning permissions, but if I'm mistaken please let me know.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 19:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-profile-allow-list-all/m-p/298884#M78283</guid>
      <dc:creator>MikeSangray2019</dc:creator>
      <dc:date>2019-11-15T19:36:31Z</dc:date>
    </item>
  </channel>
</rss>

