- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-09-2014 10:19 AM
I have a portal and 3 gateways setup working with LDAP and active directory. It is setup to use user-logon with Single Sign On. All this works without issue. What I am having issues with is I have my firewalls intergrated with LDAP and Active directory groups, I use these groups for policy rules. What I am seeing, is that the Global Protect user will sometimes show only userid in the traffic logs, and not domain\userid, at some point it will switch to using domain\userid. This is causing me issues. Any thoughts?
10-09-2014 10:21 AM
I have usually seen this issue when "Enable Server Session Read" is enabled and the user tries to access any resources such as printers etc. Can you check if it is enabled and try disabling it if possible ?
Hope it helps !
10-09-2014 10:22 AM
Where is that setting?
10-09-2014 10:25 AM
On the UserID agent or on the firewall (if Agentless)
10-09-2014 10:29 AM
I have about 21 user id agents servers spread out across the globe, the default setting is set to 'NO' for Enable Server Session Read.
10-09-2014 10:35 AM
Do you by any chance the same user in the local database on the firewall ?
10-09-2014 10:39 AM
No local users configured.
10-09-2014 10:45 AM
Also can you verify if domain name is correctly configured in server profile that you are using in the authentication profile for authentication in GP.
10-09-2014 10:54 AM
In the ldap server profile I left the domain blank, but when do a show user user-ids match i get domain\user. I added the domain local name to the server profile. When I tested global connect the traffic logs showed the id without the domain, but then switched over to domain\user after about a minute. not sure if i just caught it on the cycle or not.
10-09-2014 11:00 AM
markk96 Make sure it is the netbios domain name, to find out netbios domain name: How to Determine the NetBIOS Domain for LDAP Server Profile in Windows 2003 and 2008 Server
10-09-2014 11:01 AM
I did put the netbios name in, so far so good. Thank you so much.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!