<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RADIUS And Open LDAP Integration. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427166#M94583</link>
    <description>&lt;P&gt;Edit the radius auth profile and add the required domain into the user domain box.&lt;/P&gt;&lt;P&gt;leave the username modifier alone and the domain info will not be passed onto radius auth but will be added in user id when radius auth is successful.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Aug 2021 19:13:41 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2021-08-16T19:13:41Z</dc:date>
    <item>
      <title>RADIUS And Open LDAP Integration.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/426977#M94564</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have come through as a requirement from one of my clients, They are using RADIUS Server for RSA authentication for globalprotect, but in USER ID they are using OpenLDAP, So in the ip-user-mapping, Whenever user connecting to globalprotect, I can see the user detecting from the GP and the only as "username", but the customer has configured a user group based policy and the user detected as "domain\username".&lt;BR /&gt;&lt;BR /&gt;Due to this user traffic not hitting on the user-based policy, Is there a way we can integrate RADIUS and LDAP for globalprotect. Or any other suggestion to achieve this with another workaround.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 06:35:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/426977#M94564</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2021-08-16T06:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS And Open LDAP Integration.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427045#M94571</link>
      <description>&lt;P&gt;As far as I know PA can use RADIUS user groups only in authentication profiles (checking if user belongs to certain group after succesful authentication).&lt;/P&gt;&lt;P&gt;For security (or any other) policies PA can only use user groups obtained from LDAP servers. So consider switching GP authentication to LDAP.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 10:12:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427045#M94571</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2021-08-16T10:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS And Open LDAP Integration.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427166#M94583</link>
      <description>&lt;P&gt;Edit the radius auth profile and add the required domain into the user domain box.&lt;/P&gt;&lt;P&gt;leave the username modifier alone and the domain info will not be passed onto radius auth but will be added in user id when radius auth is successful.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 19:13:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427166#M94583</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-08-16T19:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS And Open LDAP Integration.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427273#M94592</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was thinking about this once, but never tried it. Can you confirm this works?&lt;/P&gt;&lt;P&gt;Also usernames between Open LDAP and RADIUS will have to match.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 08:57:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427273#M94592</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2021-08-17T08:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS And Open LDAP Integration.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427405#M94603</link>
      <description>&lt;P&gt;It works with local auth profile so will work with others..&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i assume that if a user logs into a domain as domain\fred.smith then he probably wont log into radius as kevin roberts.... &amp;nbsp;but yes you are correct and i have seen stranger things....&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 19:46:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427405#M94603</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-08-17T19:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS And Open LDAP Integration.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427481#M94612</link>
      <description>&lt;P&gt;Haha, true that.&lt;/P&gt;&lt;P&gt;Tho I've seen different variatons to derive username from name and surname &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I assume in OP's case it's just a radius proxy for MFA which uses LDAP as source of identities anyway.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Aug 2021 06:47:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/427481#M94612</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2021-08-18T06:47:39Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS And Open LDAP Integration.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/428226#M94689</link>
      <description>&lt;P&gt;Hi Mick,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue resolved, With the below KB Article,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm0JCAS" target="_blank" rel="noopener noreferrer"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm0JCAS&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 21 Aug 2021 03:19:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-and-open-ldap-integration/m-p/428226#M94689</guid>
      <dc:creator>SubaMuthuram</dc:creator>
      <dc:date>2021-08-21T03:19:33Z</dc:date>
    </item>
  </channel>
</rss>

