RedHat IPA authentication on Palo Alto

Reply
Highlighted
L0 Member

RedHat IPA authentication on Palo Alto

Hi,

 

When using RedHat or CentOS IPA authentication on Palo Alto firewall, we may ran into challenges when adding LDAP Server Profile and GP Clients functionality related issues.

  1. LDAP Server Profile - On a traditional RedHat or CentOS IPA server there will be multiple ou under the Base DN, In order to work properly along with Palo Alto Server profile. we have to choose the right ou as 
    Spoiler
    cn=accounts,dc=example,dc=com
    Note :- On IPA environment Containers(cn) are replaced by uid and Organization Units(ou) are replaced by cn.
  2. GP Client functionality related issue - Recent release of Linux GP client both UI and CLI based version may not work properly. Issue are, unable to open the application, input cannot be performed on the GP Applications for IPA Based users. To over come this make sure that the users shell is bash by default.

 

Thanks!

Highlighted
Community Team Member

Re: RedHat IPA authentication on Palo Alto

Hi @vjbennet ,

 

Awesome information ! Thanks for the heads up !

 

Cheers,

-Kiwi

 
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!