<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication issue with Global Protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/387546#M90393</link>
    <description>&lt;P&gt;Perhaps i have not read this correctly but you mention multiple groups.. yet you only have one group included in your screen shot. Are we talking nested groups here?&lt;/P&gt;</description>
    <pubDate>Wed, 24 Feb 2021 07:03:13 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-02-24T07:03:13Z</dc:date>
    <item>
      <title>Authentication issue with Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/387518#M90388</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We are having difficulty with our Active/Passive pair of PA_820’s where they are setup to allow auth to GlobalProtect based on AD group membership.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If we create a new OU in AD and move a user to the newly created AD OU whilst still having the same group membership, they can no longer&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;auth to connect to global protect from internal nor external networks.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If we then move them back to the original OU, auth works again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have tried the&amp;nbsp;reset, refresh and clear commands (&lt;/SPAN&gt;debug user-id reset group-mapping all, debug user-id refresh group-mapping all, clear user-cache all)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have also tried to drop the bind one level down. Any further ideas how to resolve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;PANOS version – 9.1.3&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;GlobalProtect version – 5.1.1&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Group Mapping.jpg" style="width: 625px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30038i9B8E5FCDDF63819E/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Group Mapping.jpg" alt="Group Mapping.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Auth Profile.png" style="width: 601px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30039iE1A9B6FAC191E723/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Auth Profile.png" alt="Auth Profile.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 02:37:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/387518#M90388</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2021-02-24T02:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication issue with Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/387525#M90389</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/98673"&gt;@FarzanaMustafa&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;So you can actually view group membership directly on the firewall via the&amp;nbsp;&lt;EM&gt;show user group name &amp;lt;value&amp;gt;&amp;nbsp;&lt;/EM&gt;command and make sure that the user is properly showing up in the group membership list. Next I would see what the test authentication gives you on the firewall itself (&lt;EM&gt;test authentication authentication-profile &amp;lt;value&amp;gt; username &amp;lt;value&amp;gt; password&lt;/EM&gt;&amp;nbsp;). That can sometimes point you in the right direction.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 04:41:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/387525#M90389</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-02-24T04:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication issue with Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/387546#M90393</link>
      <description>&lt;P&gt;Perhaps i have not read this correctly but you mention multiple groups.. yet you only have one group included in your screen shot. Are we talking nested groups here?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 07:03:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/387546#M90393</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-24T07:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication issue with Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/388736#M90533</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Strangely,&amp;nbsp;VPN group is working fine after clearing cache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;No nested groups in use.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 01:39:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-issue-with-global-protect/m-p/388736#M90533</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2021-03-03T01:39:10Z</dc:date>
    </item>
  </channel>
</rss>

