Global Protect Authentication Local User and AD user to allow both

Reply
Highlighted
L1 Bithead

Global Protect Authentication Local User and AD user to allow both

Hello,

I am setting up VPN on the Palo Alto. So far, I was using a local user database and it is working fine. I will need to move to AD authentication and tested ok.

 

However, the issue  I am getting if that I can use only one type of authentication at a time by moving the authentication profile type up on the GlobalProtect Portal>Authentication> Client Authentication.

 

In this, I have configured two authentication profile  Local and AD and only the top is working.

The local user is for external suppliers and I need to keep that.

 

Can you please help ?

 

 


Accepted Solutions
Highlighted
L1 Bithead

Capture.PNG

Attached the configuration.

View solution in original post


All Replies
Highlighted
L1 Bithead

Capture.PNG

Attached the configuration.

View solution in original post

Highlighted
L3 Networker

Hi,

 

you can use authentication sequence, where you enter all Authentication profiles to be use for login.

from Device > Authentication sequence. create new sequence and select all needed profiles, and use this sequence-entry in GP (Portal/Gateway)

 

*************************************************************
PCCSA | PCNSA | PCNSE | CyberRange | PA CyberForce
*********************************
Highlighted
L1 Bithead

Thanks Abdul very much.

The authentication worked perfectly for both.

 

Highlighted
L3 Networker

you are welcome.

Can you mark the right correct answer?, thanks.

*************************************************************
PCCSA | PCNSA | PCNSE | CyberRange | PA CyberForce
*********************************
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!