Global Protect Authentication Local User and AD user to allow both

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect Authentication Local User and AD user to allow both

L1 Bithead

Hello,

I am setting up VPN on the Palo Alto. So far, I was using a local user database and it is working fine. I will need to move to AD authentication and tested ok.

 

However, the issue  I am getting if that I can use only one type of authentication at a time by moving the authentication profile type up on the GlobalProtect Portal>Authentication> Client Authentication.

 

In this, I have configured two authentication profile  Local and AD and only the top is working.

The local user is for external suppliers and I need to keep that.

 

Can you please help ?

 

 

1 accepted solution

Accepted Solutions

L1 Bithead

Capture.PNG

Attached the configuration.

View solution in original post

4 REPLIES 4

L1 Bithead

Capture.PNG

Attached the configuration.

L4 Transporter

Hi,

 

you can use authentication sequence, where you enter all Authentication profiles to be use for login.

from Device > Authentication sequence. create new sequence and select all needed profiles, and use this sequence-entry in GP (Portal/Gateway)

 

Thanks Abdul very much.

The authentication worked perfectly for both.

 

you are welcome.

Can you mark the right correct answer?, thanks.

  • 1 accepted solution
  • 3218 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!