<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect + LDAP + Cert Auth = Auth Fail AND Auth Success in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10985#M8111</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Hardik.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a bug that was fixed in 5.0.14 your support engineer should be able to give you the bug number and a reference in the release notes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Aug 2014 20:03:54 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2014-08-26T20:03:54Z</dc:date>
    <item>
      <title>Global Protect + LDAP + Cert Auth = Auth Fail AND Auth Success</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10983#M8109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is anyone else running this setup...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global Protect VPN(iPads specifically) using LDAP(Active Directory) AND client certificate for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...if you are, have you noticed in the System logs, when a user authenticates to Global Protect the PA logs one or two Auth Fails followed by an Auth Success?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our users are not noticing anything on their end, but looking at packet captures, it looks like the PA never sends the LDAP request for the first two Auth Fails, then finally sends it on the third Auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently on 5.0.11.&amp;nbsp; PA Support says to upgrade to 5.0.14, although I did not read anything in the release notes about this being fixed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 14:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10983#M8109</guid>
      <dc:creator>jambulo</dc:creator>
      <dc:date>2014-08-26T14:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect + LDAP + Cert Auth = Auth Fail AND Auth Success</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10984#M8110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jambulo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have seen packet capture, and verified firewall didnt send packets in first two attempts. Then its certainly a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before upgrade to 5.0.14, you should ask engineer for root cause. And also ask for bug which suggested upgrade to 5.0.14.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will ensure, you will not have same issue after moving to 5.0.14.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 17:49:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10984#M8110</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-08-26T17:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect + LDAP + Cert Auth = Auth Fail AND Auth Success</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10985#M8111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree with Hardik.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a bug that was fixed in 5.0.14 your support engineer should be able to give you the bug number and a reference in the release notes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Aug 2014 20:03:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10985#M8111</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-26T20:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect + LDAP + Cert Auth = Auth Fail AND Auth Success</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10986#M8112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jambulo&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another idea.&lt;/P&gt;&lt;P&gt;How looks Your authentication sequence?&lt;/P&gt;&lt;P&gt;Is ther only one profile on profile list?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I observed similar logs entries when I have two profiles in one authentication sequence, so PAN tryed to authenticate on first profile and then on next one if was unable to authenticate on the first.&lt;/P&gt;&lt;P&gt;Please verify that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Aug 2014 09:27:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-ldap-cert-auth-auth-fail-and-auth-success/m-p/10986#M8112</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-27T09:27:19Z</dc:date>
    </item>
  </channel>
</rss>

