AD group for administratoin using authentication through LDAP

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

AD group for administratoin using authentication through LDAP

Not applicable

I'm trying to authenticate an AD group for administrative access for our PA. I'm missing the last step to implement it and I may have some of the steps messed up. could someone fill in the blanks for me?

  1. Create an LDAP profile
  2. Create an authentication profile
  3. ???

Sorry if this question has been covered before.

Thanks

1 accepted solution

Accepted Solutions

It would be per user.

If you would like to use user groups on AD, then you can try to use RADIUS since with RADIUS, you can return attributes for authorization (which cannot be done with LDAP - hence each user has to be created on the firewall, assigned a role and authenticated remotely).

Here is a document describing the configuration for RADIUS with VSA for your reference: https://live.paloaltonetworks.com/docs/DOC-1765

View solution in original post

4 REPLIES 4

L7 Applicator

#3. Create an administrator under Device>administrators and assign the auth profile from #2 to the user.

In the administrator section, can I use the AD group name (such as "firewall Admins") or will it have to be per individual user within that group?

It would be per user.

If you would like to use user groups on AD, then you can try to use RADIUS since with RADIUS, you can return attributes for authorization (which cannot be done with LDAP - hence each user has to be created on the firewall, assigned a role and authenticated remotely).

Here is a document describing the configuration for RADIUS with VSA for your reference: https://live.paloaltonetworks.com/docs/DOC-1765

thank you, exactly what I wanted to know.

  • 1 accepted solution
  • 2918 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!