09-25-2012 04:24 AM
Having upgraded our Panorama from 4.1.7 to 4.1.8 - we can no longer use the LDAP user authentication.
The user constantly gets "invalid username or password" (same message on the Panorama) - yet this worked without any problems with 4.1.7
On Panorama - one can see that in the LDAP profile - the Base option is never getting populated (dropdown option is only "none" rather than domain name).
Is this a new "feature" ?
09-27-2012 01:45 AM
Confirming that after removing the domain entry I was able to log on with my domain account.
The bind section however - will still not populate. It has to be there thou for the authentication to work.
So step forward - but not something I will try on my firewalls
09-27-2012 01:53 AM
Yes, it works without "domain" entry
On prior Version it works also without this entry. So where is it used for?
10-01-2012 09:20 AM
Confirmed on PA5020 that removing the "doman" entry in Kerberos resolved login issue on 4.1.8.
10-02-2012 11:30 AM
Confirmed here as well on PA2050.
10-29-2012 08:32 AM
Ive had to flip the "domain" entry setting back and forth to get LDAP to work correctly.
I would remove it, and it would work for a while....then I would have to add it back and then remove it to get it to work again.
Tech support has now suggested to me that I go back to version 4.1.7-h2
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!