when I configure LDAP for authentication,
then I'm getting the groups in the distinguished name (dn) format.
I can choose them in policies and in the authentication profile.
Now my questions,
is the pan-agent then needed for policy authentication, too? Please explain why!
when I add a group in the dn format to the allow list
of an authentication profile, then it seems to be not matching when I'm trying to authenticate,
I have to add the users espacilly, is this right, or is the ldap connection not working correct?
yes you can authenticate users for SSL-VPN, Captive Portal!
Then you have to authenticate active with your user credentials.
And then you can use the LDAP groups in you policies.
But if you want transparently authenticate the users,
then you are right you need the agent for the user-ip-mapping.
That is what I get, when I was testing.
Hope that helps.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!