- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-27-2021 08:18 AM
Hi Team,
We had configured LDAP authentication on Palo alto firewall.
The LDAP server had been configured and we had checked the connectivity and it was successful. Created an group mapping and included an group in the include group mapping.
Checked the groups and the user details via CLI of the firewall and could see that the user under the included group configurations is being fetched by the firewall.
When configuring authentication profile we could see that the group is included in the authentication profile but the user in the group is not being authenticated but when the allow list is selected as all under the authentication profile the Authentication is happening properly.
Regards,
Tamilvanan.
12-27-2021 09:58 AM
Hello,
What I have seen is that somethings dont like nested groups. List the groups by itself and not nested and see if it works.
Regards,
12-28-2021 07:36 AM - edited 12-28-2021 07:38 AM
Hi @tamilvanan ,
Does the username format in the "show user ip-user-mapping all" command match the username format in the "show user group name cn=blah,cn=blah,dc=blah,dc=blah" command? (The "show user group list" command will give you the exact group name for the previous command.) If the format does not match exactly, then the user may not be matched to the group. There are some things you can do to fix the issue:
Thanks,
Tom
12-28-2021 08:33 AM
Hi @OtakarKlier @TomYoung Thanks for providing your valuable inputs.
After posting this issue I was searching for documentation on this issue and came across the doc mentioned .
On the Authentication profile and Group mapping settings we had defined abc.com the full DNS name in the domain box. We had modified it to abc on both Group mapping and the Auth profile and the users in that particular groups started getting authenticated when testing using the test auth-profile command.
12-28-2021 09:01 AM
Hi @tamilvanan ,
That's exactly what I said in #1 above! Glad you got it working. BTW, your URL points to webdefense. You may want to fix it.
Thanks,
Tom
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!