- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
05-16-2013 11:22 AM
I'm trying to authenticate an AD group for administrative access for our PA. I'm missing the last step to implement it and I may have some of the steps messed up. could someone fill in the blanks for me?
Sorry if this question has been covered before.
Thanks
05-16-2013 12:11 PM
It would be per user.
If you would like to use user groups on AD, then you can try to use RADIUS since with RADIUS, you can return attributes for authorization (which cannot be done with LDAP - hence each user has to be created on the firewall, assigned a role and authenticated remotely).
Here is a document describing the configuration for RADIUS with VSA for your reference: https://live.paloaltonetworks.com/docs/DOC-1765
05-16-2013 11:42 AM
#3. Create an administrator under Device>administrators and assign the auth profile from #2 to the user.
05-16-2013 11:51 AM
In the administrator section, can I use the AD group name (such as "firewall Admins") or will it have to be per individual user within that group?
05-16-2013 12:11 PM
It would be per user.
If you would like to use user groups on AD, then you can try to use RADIUS since with RADIUS, you can return attributes for authorization (which cannot be done with LDAP - hence each user has to be created on the firewall, assigned a role and authenticated remotely).
Here is a document describing the configuration for RADIUS with VSA for your reference: https://live.paloaltonetworks.com/docs/DOC-1765
05-16-2013 01:49 PM
thank you, exactly what I wanted to know.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!