Panorama 4.1.8 LDAP Failure

Reply
cparrish
Not applicable

What is the command line to restart User-ID ?

gswcowboy
L6 Presenter

check pid first

admin@oliver(active)> show system resources | match userid

2312       20   0  170m  57m  37m S    0  2.3   3:38.91 useridd

admin@oliver(active)> debug software restart user-id

check pid once more after restart to confirm pid change.

OsramSecurity
L0 Member

We have investigated the changes in version 4.1.8. and can share our findings:

a) Administrator login now REQUIRES the domain field to be EMPTY

b) User identification generally REQUIRES the domain field to be SET

Until version 4.1.6. wit domain field set everything worked as expected, with 4.1.8. you need to create LDAP/Kerberos settings twice, one entry WITH and one W/O domain name. In addition Authentication sequence must be configured twice as well. Then for Admin accounts you select the Auth Profile with empty domains and for User identification (and possibly other purposes) you select the groups with domain fields set. Not nice but it works.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!