RedHat IPA authentication on Palo Alto

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

RedHat IPA authentication on Palo Alto

L0 Member

Hi,

 

When using RedHat or CentOS IPA authentication on Palo Alto firewall, we may ran into challenges when adding LDAP Server Profile and GP Clients functionality related issues.

  1. LDAP Server Profile - On a traditional RedHat or CentOS IPA server there will be multiple ou under the Base DN, In order to work properly along with Palo Alto Server profile. we have to choose the right ou as 
    Spoiler
    cn=accounts,dc=example,dc=com
    Note :- On IPA environment Containers(cn) are replaced by uid and Organization Units(ou) are replaced by cn.
  2. GP Client functionality related issue - Recent release of Linux GP client both UI and CLI based version may not work properly. Issue are, unable to open the application, input cannot be performed on the GP Applications for IPA Based users. To over come this make sure that the users shell is bash by default.

 

Thanks!

3 REPLIES 3

Community Team Member

Hi @vjbennet ,

 

Awesome information ! Thanks for the heads up !

 

Cheers,

-Kiwi

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

L1 Bithead

Dear Kiwi,

 

How can i integrate with the Redhat IPA server authentication on Palo Alto Firewall, I can't find documentation for this cloud you please share or guide for the configuration.

 

Many Thanks.

 

  • 3540 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!