GlobalProtect Authentication with both Active Directory and local accounts

Reply
Highlighted
L1 Bithead

GlobalProtect Authentication with both Active Directory and local accounts

Hello,

 

I'm deploying a GlobalProtect VPN and I'm facing a problem in the Authentication.

 

I have both LDAP and Local authentication profile that are configured and I want to be able to connect with either an account in the Active Directory or the local database.

 

The problem is in the Gateway configuration, in the Authentication tab, I put both of my authentication profiles but only the 1st one is used. If the 1st is the local Authentication profile, I'm able to connect only with local accounts. If the 1st one is the LDAP Authentication profile, only with Active Directory accounts.

 

Is there something I am doing wrong or is it just the normal behavior of the Gateway ?

 

BR

 

Nael

L7 Applicator

Re: GlobalProtect Authentication with both Active Directory and local accounts

Device > Authentication Sequence

 

Apply sequence as auth profile.

Enterprise Architect @ Cloud Carib www.cloudcarib.com
ACE (3.0, 5.0, 6.0, 7.0), PCNSE (6, 7), PCNSI
L7 Applicator

Re: GlobalProtect Authentication with both Active Directory and local accounts

Hi @Naelwan

 

If you use an authentication sequence it is possible to use both local and AD.

In the authentication sequence you can add the local and the LDAP authenticarion profile. These profiles will then be checked, as the name already says, in sequence. So if you have AD first, then this will be checked. If there is no user with the entered name or the password is wrong, then the second, local profile, will be checked to authenticate the user.

L1 Bithead

Re: GlobalProtect Authentication with both Active Directory and local accounts

Thanks @Raido & @vsys_remo !

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!