Panorama 4.1.8 LDAP Failure

cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
We are conducting regularly scheduled maintenance over the weekend, which could cause some downtime on LIVEcommunity. We apologize for any inconvenience.

Panorama 4.1.8 LDAP Failure

Not applicable

Having upgraded our Panorama from 4.1.7 to 4.1.8 - we can no longer use the LDAP user authentication.

The user constantly gets "invalid username or password" (same message on the Panorama) - yet this worked without any problems with 4.1.7

On Panorama - one can see that in the LDAP profile - the Base option is never getting populated (dropdown option is only "none" rather than domain name).

Is this a new "feature" ?

Br

JørgeDA

22 REPLIES 22

What is the command line to restart User-ID ?

check pid first

admin@oliver(active)> show system resources | match userid

2312       20   0  170m  57m  37m S    0  2.3   3:38.91 useridd

admin@oliver(active)> debug software restart user-id

check pid once more after restart to confirm pid change.

We have investigated the changes in version 4.1.8. and can share our findings:

a) Administrator login now REQUIRES the domain field to be EMPTY

b) User identification generally REQUIRES the domain field to be SET

Until version 4.1.6. wit domain field set everything worked as expected, with 4.1.8. you need to create LDAP/Kerberos settings twice, one entry WITH and one W/O domain name. In addition Authentication sequence must be configured twice as well. Then for Admin accounts you select the Auth Profile with empty domains and for User identification (and possibly other purposes) you select the groups with domain fields set. Not nice but it works.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!