LDAP Authentication not working when using include group settings

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

LDAP Authentication not working when using include group settings

L3 Networker

Hi Team,

 

We had configured LDAP authentication on Palo alto firewall.

 

The LDAP server had been configured and we had checked the connectivity and it was successful. Created an group mapping and included an group in the include group mapping. 

 

Checked the groups and the user details via CLI of the firewall and could see that the user under the included group configurations is  being fetched by the firewall.

 

When configuring authentication profile we could see that the group is included in the authentication profile but the user in the group is not being authenticated but when the allow list is selected as all under the authentication profile the Authentication is happening properly.

 

Regards,

Tamilvanan.

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello,

What I have seen is that somethings dont like nested groups. List the groups by itself and not nested and see if it works.

 

Regards,

Cyber Elite
Cyber Elite

Hi @tamilvanan ,

 

Does the username format in the "show user ip-user-mapping all" command match the username format in the "show user group name cn=blah,cn=blah,dc=blah,dc=blah" command?  (The "show user group list" command will give you the exact group name for the previous command.)  If the format does not match exactly, then the user may not be matched to the group.  There are some things you can do to fix the issue:

 

  1. Make sure the domain specified under Device > Authentication Profile > [LDAP Authenticaton Profile] > Authentication > User Domain matches the domain under Device > User Identification > Group Mapping Settings > [edit] > Server Profile.
  2. Follow the guidelines in this doc -> https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-new-features/user-id-features/support-for-multip....  The primary and alternate usernames can fix it as well as the matching without domains if the domain is different or missing.

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.

L3 Networker

Hi @OtakarKlier @TomYoung  Thanks for providing your valuable inputs.

 

After posting this issue I was searching for documentation on this issue and came across the doc mentioned .

 

On the Authentication profile and Group mapping settings we had defined abc.com the full DNS name in the domain box. We had modified it to abc on both Group mapping and the Auth profile and the users in that particular groups started getting authenticated when testing using the test auth-profile command.

 

 

Global Protect Login Fails When Using a Group in the Allow List

Cyber Elite
Cyber Elite

Hi @tamilvanan ,

 

That's exactly what I said in #1 above!  Glad you got it working.  BTW, your URL points to webdefense.  You may want to fix it.

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 3593 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!