- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
03-30-2011 09:36 PM
Hi,
Apologies if this has already been discussed. I post this message, because I can't find a clear answer to my questions, related to the admin access to the box via LDAP. Basically, what I can't find is the guide for setting up LDAP admin accounts.
- Version used: 3.1.8.
- Motivation: use of LDAP so that password policy is managed at the AD level. Goal is to keep one emergency account in local DB, and have all other admin accounts taken from LDAP.
- In Device > Setup, there is a parameter 'Authentication Profile' with the following comment: 'Authentication profile to use for non-local admins. Only RADIUS method is supported'. Why only Radius? I don't know if this should be understood as 'prefer radius to ldap'?
- Basic configuration steps seem to be:
1. create the 'Server Profiles > LDAP' profile for access to LDAP servers
2. create an 'Authentication Profile': the 'Allow list' seems to be taken from UIA data, whereas the Login attribute has to be specified according to LDAP Server profile... this is very confusing.
3. create the administrator in 'Administrators' with the Authentication Profile set to the one created: the name chosen will be appended to domain name defined for the LDAP Server profile. Then what happens if a local account has the same name than an LDAP account?
In summary, lots of suppositions. Any help welcomed. And if there is a guide already available that I have missed, please advise.
Thanks
03-31-2011 02:44 PM
Hello,
Please refer to the below link for the document you need to help with your configuration.
https://live.paloaltonetworks.com/docs/DOC-1445
Thanks,
Phil
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!