- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-08-2021 02:04 AM
Restriction of the users on the GP portal page.
We selected a particular group in the allowed list, but authentication was failing unless we select all.
06-09-2021 05:04 AM
My Actual Issue,
GlobalProtect Portal or Agent users fail authentication
My Authentication Profile has specific filtered groups. The users appear to be in the group that makes up the allow list. However, the message "user not in allow list" still appears. If the allow list is changed to have "all" rather than specific groups, the user authenticates fine.
And I followed this link https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC
06-08-2021 08:35 AM
from cli... type
show user group list
then type
show user group name "name of the group required"
check that the users are all in the group as expected and also check the domain\username is the same domain as auth profile user domain setting.
try that for starters...
06-08-2021 10:21 AM
Hi @Mohammed_Yasin ,
Almost every time I have seen this behaviour it is caused by differences how the group mapping is reporting the users and how the authentication profile is logging the username - mainly in the domain.
If your authentication profile is accepting only username (without domain) as user input, while the group mapping is returning domain/username.
@Mick_Ball already give you steps how to check what format are you receiving from group mapping.
06-08-2021 10:33 AM
Do you restrict the users directly in the portal configuration or in the authentication profile?
If you use the portal configuration, were you able to choose the group from the dropdown? If not, did you also try to enter the DN of the group (all lowercase)?
06-09-2021 05:04 AM
My Actual Issue,
GlobalProtect Portal or Agent users fail authentication
My Authentication Profile has specific filtered groups. The users appear to be in the group that makes up the allow list. However, the message "user not in allow list" still appears. If the allow list is changed to have "all" rather than specific groups, the user authenticates fine.
And I followed this link https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!