GlobalProtect Authentication with both Active Directory and local accounts

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GlobalProtect Authentication with both Active Directory and local accounts

L1 Bithead

Hello,

 

I'm deploying a GlobalProtect VPN and I'm facing a problem in the Authentication.

 

I have both LDAP and Local authentication profile that are configured and I want to be able to connect with either an account in the Active Directory or the local database.

 

The problem is in the Gateway configuration, in the Authentication tab, I put both of my authentication profiles but only the 1st one is used. If the 1st is the local Authentication profile, I'm able to connect only with local accounts. If the 1st one is the LDAP Authentication profile, only with Active Directory accounts.

 

Is there something I am doing wrong or is it just the normal behavior of the Gateway ?

 

BR

 

Nael

2 accepted solutions

Accepted Solutions

Cyber Elite
Cyber Elite

Device > Authentication Sequence

 

Apply sequence as auth profile.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

View solution in original post

L7 Applicator

Hi @Naelwan

 

If you use an authentication sequence it is possible to use both local and AD.

In the authentication sequence you can add the local and the LDAP authenticarion profile. These profiles will then be checked, as the name already says, in sequence. So if you have AD first, then this will be checked. If there is no user with the entered name or the password is wrong, then the second, local profile, will be checked to authenticate the user.

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

Device > Authentication Sequence

 

Apply sequence as auth profile.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

L7 Applicator

Hi @Naelwan

 

If you use an authentication sequence it is possible to use both local and AD.

In the authentication sequence you can add the local and the LDAP authenticarion profile. These profiles will then be checked, as the name already says, in sequence. So if you have AD first, then this will be checked. If there is no user with the entered name or the password is wrong, then the second, local profile, will be checked to authenticate the user.

L1 Bithead

Thanks @Raido_Rattameister & @Remo !

  • 2 accepted solutions
  • 5328 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!