<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH to Management interface (RADIUS Auth) PAN OS 10.0.4 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-to-management-interface-radius-auth-pan-os-10-0-4/m-p/399595#M91556</link>
    <description>&lt;P&gt;I also noted the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Due to a SAML authentication need, we have the default username set to UPN so that group memberships are seen accurately. When I specify the Username modifier for the RADIUS profile to be %USERINPUT%@%USERDOMAIN%&amp;nbsp;&amp;nbsp;the allow list check begins failing for the auth profile. Wouldn't it stand to reason the Username modifier should be applied before the group check is performed? Wouldn't it also make sense to honor the alternate username defined in the group mapping settings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;I can get the SSH connection to work by setting the auth profile to allow all, and updating the Username modifier as per the above. This makes me think it doesn't like the format of %USERNAME%@%DOMAIN%@%FW-ADDRESS%. I know SSH can do this format because I've used it in other implementations. The question becomes, how to get the group mappings for SAML and RADIUS to both play nicely on the same domain without querying the groups twice..... for now I have 2 group mapping settings defined, one for SAML and one for RADIUS with the different groups in each.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Opened a ticket and will report back if I find anything else out.&lt;/P&gt;</description>
    <pubDate>Sat, 17 Apr 2021 02:12:32 GMT</pubDate>
    <dc:creator>D_Baerry</dc:creator>
    <dc:date>2021-04-17T02:12:32Z</dc:date>
    <item>
      <title>SSH to Management interface (RADIUS Auth) PAN OS 10.0.4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-to-management-interface-radius-auth-pan-os-10-0-4/m-p/399571#M91555</link>
      <description>&lt;P&gt;Working on an HA Pair of PA-820 firewalls and just finished configuring auth for management interfaces. Went to test, and found that the firewall said auth succeeds, but the SSH connection immediately drops.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Auth profile is RADIUS (Windows NPS server)&lt;/LI&gt;&lt;LI&gt;PAN OS 10.0.4&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Tests:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Authentication to web interface works for user via RADIUS profile&lt;/LI&gt;&lt;LI&gt;Authentication to SSH interface says authenticated in the system log, but the SSH connection immediately drops&lt;UL&gt;&lt;LI&gt;Tried connection via SSH client on a Mac, Putty, and Windows SSH client. All yield the same results.&lt;/LI&gt;&lt;LI&gt;debug log for SSH client shows nothing&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Authentication to SSH via local user accounts on the firewall have no issue&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone seen this before? Possible bug?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 23:31:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-to-management-interface-radius-auth-pan-os-10-0-4/m-p/399571#M91555</guid>
      <dc:creator>D_Baerry</dc:creator>
      <dc:date>2021-04-16T23:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Management interface (RADIUS Auth) PAN OS 10.0.4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-to-management-interface-radius-auth-pan-os-10-0-4/m-p/399595#M91556</link>
      <description>&lt;P&gt;I also noted the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Due to a SAML authentication need, we have the default username set to UPN so that group memberships are seen accurately. When I specify the Username modifier for the RADIUS profile to be %USERINPUT%@%USERDOMAIN%&amp;nbsp;&amp;nbsp;the allow list check begins failing for the auth profile. Wouldn't it stand to reason the Username modifier should be applied before the group check is performed? Wouldn't it also make sense to honor the alternate username defined in the group mapping settings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;I can get the SSH connection to work by setting the auth profile to allow all, and updating the Username modifier as per the above. This makes me think it doesn't like the format of %USERNAME%@%DOMAIN%@%FW-ADDRESS%. I know SSH can do this format because I've used it in other implementations. The question becomes, how to get the group mappings for SAML and RADIUS to both play nicely on the same domain without querying the groups twice..... for now I have 2 group mapping settings defined, one for SAML and one for RADIUS with the different groups in each.&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Opened a ticket and will report back if I find anything else out.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Apr 2021 02:12:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-to-management-interface-radius-auth-pan-os-10-0-4/m-p/399595#M91556</guid>
      <dc:creator>D_Baerry</dc:creator>
      <dc:date>2021-04-17T02:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSH to Management interface (RADIUS Auth) PAN OS 10.0.4</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssh-to-management-interface-radius-auth-pan-os-10-0-4/m-p/399602#M91557</link>
      <description>&lt;P&gt;I've got a config that is where I want it to be, and works, but seems to indicate there are 2 (possibly related) bugs. Here is the config in a nutshell:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Management Auth&lt;/U&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;RADIUS Auth Profile with the username modifier set to %USERDOMAIN%\%USERINPUT%&lt;/LI&gt;&lt;LI&gt;Allow List in Auth Profile set to Admin Group&lt;/LI&gt;&lt;LI&gt;Group Mapping Profile (pulling from LDAP) set with Primary Username to be sAMAccountName&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This setup allows me to leave the SAML config alone and login successfully to both SSH and WEBUI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Potential Bugs:&lt;/STRONG&gt;&amp;nbsp;When primary username is set to UserPrincipalName in Group Mappings&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;When Username modifier is set to &lt;A href="mailto:%USERINPUT%@%USERDOMAIN%" target="_blank" rel="noopener"&gt;%USERINPUT%@%USERDOMAIN%&lt;/A&gt;&amp;nbsp;the %USERDOMAIN% is not being applied during user mapping check&lt;/LI&gt;&lt;LI&gt;When user enters fully qualified identity for SSH login (Username modifier set to %USERINPUT%) the SSH session terminates right after successful auth&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 17 Apr 2021 02:28:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssh-to-management-interface-radius-auth-pan-os-10-0-4/m-p/399602#M91557</guid>
      <dc:creator>D_Baerry</dc:creator>
      <dc:date>2021-04-17T02:28:23Z</dc:date>
    </item>
  </channel>
</rss>

