GP portal error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

GP portal error

L4 Transporter

Restriction of the users on the GP portal page.

We selected a particular group in the allowed list, but authentication was failing unless we select all.

1 accepted solution

Accepted Solutions

My Actual Issue,

 

GlobalProtect Portal or Agent users fail authentication

My Authentication Profile has specific filtered groups. The users appear to be in the group that makes up the allow list. However, the message "user not in allow list" still appears. If the allow list is changed to have "all" rather than specific groups, the user authenticates fine.

 

And I followed this link https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC

View solution in original post

4 REPLIES 4

L7 Applicator

from cli... type

 

show user group list

 

then type 

 

show user group name "name of the group required"

 

check that the users are all in the group as expected and also check the domain\username  is the same domain as auth profile user domain setting.

 

try that for starters...

Hi @Mohammed_Yasin ,

 

Almost every time I have seen this behaviour it is caused by differences how the group mapping is reporting the users and how the authentication profile is logging the username - mainly in the domain.

If your authentication profile is accepting only username (without domain) as user input, while the group mapping is returning domain/username.

 

@Mick_Ball  already give you steps how to check what format are you receiving from group mapping.

L7 Applicator

Do you restrict the users directly in the portal configuration or in the authentication profile?

If you use the portal configuration, were you able to choose the group from the dropdown? If not, did you also try to enter the DN of the group (all lowercase)?

My Actual Issue,

 

GlobalProtect Portal or Agent users fail authentication

My Authentication Profile has specific filtered groups. The users appear to be in the group that makes up the allow list. However, the message "user not in allow list" still appears. If the allow list is changed to have "all" rather than specific groups, the user authenticates fine.

 

And I followed this link https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC

  • 1 accepted solution
  • 2957 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!