LDAP Authentication questions

Reply
Highlighted
L2 Linker

LDAP Authentication questions

Hi everyone,

when I configure LDAP for authentication,
then I'm getting the groups in the distinguished name (dn) format.
I can choose them in policies and in the authentication profile.

Now my questions,
is the pan-agent then needed for policy authentication, too? Please explain why!
when I add a group in the dn format to the allow list
of an authentication profile, then it seems to be not matching when I'm trying to authenticate,
I have to add the users espacilly, is this right, or is the ldap connection not working correct?

Regards
Christian

Highlighted
L3 Networker

Re: LDAP Authentication questions

you do not need to have pan agent to authenicate using ldap. it would seem like your ldap configuration is incorrect. please create a case and upload the tech support file for review of your ldap configuration.

Highlighted
L0 Member

Re: LDAP Authentication questions

Sorry, I didn't understand.

Are you saying that if I have OpenLDAP to authenticate users in my company I don't need User-ID Agent/API to build security policy user based?

How can I get User-IP mapping in this situation?

Thanks

Highlighted
L2 Linker

Re: LDAP Authentication questions

Hi,

yes you can authenticate users for SSL-VPN, Captive Portal!

Then you have to authenticate active with your user credentials.

And then you can use the LDAP groups in you policies.

But if you want transparently authenticate the users,

then you are right you need the agent for the user-ip-mapping.

That is what I get, when I was testing.

Hope that helps.

Regards

Christian

Highlighted
L0 Member

Re: LDAP Authentication questions

Thank you so much!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!