<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After upgradae of pan os 8. 1. 14h2 auth profile changes auto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/after-upgradae-of-pan-os-8-1-14h2-auth-profile-changes-auto/m-p/334735#M84414</link>
    <description>&lt;P&gt;&lt;FONT size="2"&gt;After Involving the senior engineer in the session started to troubleshoot the issue, hence he had noticed authentication-profile for XXXX attached to the radius, which configured for user authentication as User Domain finance.com.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;and the authentication-profile for XXXX is OTP which users get with is Passcode whenever they log in to Global protect with there AD account.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 23 Jun 2020 08:24:57 GMT</pubDate>
    <dc:creator>Mohammed_Yasin</dc:creator>
    <dc:date>2020-06-23T08:24:57Z</dc:date>
    <item>
      <title>After upgradae of pan os 8. 1. 14h2 auth profile changes auto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/after-upgradae-of-pan-os-8-1-14h2-auth-profile-changes-auto/m-p/334728#M84413</link>
      <description>&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;the PAN-OS has upgraded from 8. 1. 9h4 to 8. 1. 14h2.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;The issue has been reported that users are able to connect the VPN via Global protect with their AD logins, but unable to access few web-based applications.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;The logs are not received by the firewall in the traffic monitor, At the same time packet capture was done and counters from the firewall have done and it was a dropped in the firewall.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Meanwhile, I have observed the wrong domain names in the logs as well as User-Base policies.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Checked all LDAP and User Identification parameter settings and global protected parameters has it has configured in a standard way.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;However, I have gone to preferred PANOS version 8.1.13.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;the downgrade has done with the preferred version 8.1.13, and the issue persisted.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;checked and troubleshooted services like Client Probing /Decryption profiles /Suffix-Domain-Setting /Global Protect Gateway configuration /GP-Agent /GP-Client-settings /Gateway Group-Mapping /Interface-setting/ LDAP-Profile / LDAP-Server-monitoring/ NTP/ Security policies/ service Route /User-Group-Attributes / user -ID-mapping/ WMI-Authentication.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;A created rule set as a TEST policy with ANY ANY ANY except such &amp;amp; destination Zones with start and end session logs and Finally, we have received the logs for the same.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;From the logs, it has been recognized the sources users with a different name of content as finance.com\abcd instead of finance\abcd.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Therefore, we have replaced the source user ANY with finance.com\abcd and double-checked the application are able to access it the testing users,&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;One by one I have started to replace ANY objects with original objects on the test policy, but the issue was the same and we replace finance.com\abcd as a finance\abcd the issue was the same.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Done a comparison with Running configuration and backup files before and after activity to checks changes and it found that some of the configurations were missing like split tunneling. And other security policies.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Loaded the backup file 2-day old one which has taken from the firewall before the up-gradation activity and no changes have made after loading in the firewall, but the issue was the same. Again, no logs can see in the traffic monitor.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Again, I started to troubleshoot with further services like User Identification parameters Global protect configuration and LDAP services.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Cleared the User ID caches and Session caches and Created a test policy and troubleshoot with scenarios, but does help to fix the username Conflicts&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;However, due to a short time decided to revert to original setup 8. 1. 9-h4 and GP software 4.1.11 as before the activity of upgrade&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;As reverted to the actual setup of before the upgrade activity and loaded the backup file of 1 week old to the firewall and the issue the same as it was in version 8. 1. 14h2 and 8.1.13.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;After uploading the 1-week old backup file in the firewall and No changes have been made meanwhile, I have involved the senior engineer for further troubleshooting.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Involving the senior engineer in the session started to troubleshoot the issue, hence he had noticed authentication-profile for XXXX attached to the radius, which configured for user authentication as User Domain finance.com.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;He has replaced the finance.com as finance and saved the parameter of authentication-profile and committed the configuration.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;After changed It has stopped the conflicts between finance and finance.com and the application started to work for global protect users&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;As it was misconfiguration error and it has reconfigured in the Device à Authentication à Profile Changing “User Domain" parameter, and the issue fixed.&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;backup files of the 1-week old one and 2-day old one have loaded to the firewall and it was not working, but after changing parameters in the backup file of 1 week and the issue has been fixed.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT size="2"&gt;Checked all configuration of the system. no changes have done with auth profiles. For the last 5 months.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;I want to know the cause of this incident.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 08:21:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/after-upgradae-of-pan-os-8-1-14h2-auth-profile-changes-auto/m-p/334728#M84413</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-23T08:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: After upgradae of pan os 8. 1. 14h2 auth profile changes auto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/after-upgradae-of-pan-os-8-1-14h2-auth-profile-changes-auto/m-p/334735#M84414</link>
      <description>&lt;P&gt;&lt;FONT size="2"&gt;After Involving the senior engineer in the session started to troubleshoot the issue, hence he had noticed authentication-profile for XXXX attached to the radius, which configured for user authentication as User Domain finance.com.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;and the authentication-profile for XXXX is OTP which users get with is Passcode whenever they log in to Global protect with there AD account.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2020 08:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/after-upgradae-of-pan-os-8-1-14h2-auth-profile-changes-auto/m-p/334735#M84414</guid>
      <dc:creator>Mohammed_Yasin</dc:creator>
      <dc:date>2020-06-23T08:24:57Z</dc:date>
    </item>
  </channel>
</rss>

