Ubuntu_OpenLDAP with PAN-OS User id

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Ubuntu_OpenLDAP with PAN-OS User id

L4 Transporter

Hi All,

 

Is there any document which will show how to configure Ubuntu based OpenLADP as a user id agent with Palo Alto firewalls.

 

How to add the LDAP server into Server monitoring profile. 

 

 

Snow
5 REPLIES 5

Cyber Elite
Cyber Elite

Hello there

 

You can use this article https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGnCAK

Or you can look at the Admin guide:  https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-web-interface-help/device/device-server-profiles...

 

Help the community: Like helpful comments and mark solutions

L1 Bithead

Hi @SubaMuthuram,

Is it done ?

integrating OpenLDAP with PA firewall.

 

Here i have a scenario where i have configured OpenLDAP for Global Protect and Captive Portal authentication, Which is working fine.

 

But i need to configure Server monitoring (PANOS User-ID agent) or Windows User-ID agent integration for fetching user to IP mapping details.

But i cant find any documents regarding this.

Iam unable to install User-ID agent into my Linux server where i enabled OpenLDAP.

 

Please help me in this if you found a solution.

 

Thanks in advance.

 

Hi @Arun_R 

The user agent software is only for windows not for Linux, you only can use the user-id integration agent into the firewall

The monitored server only works for this services

Alejandro_Hernandez_0-1707408537415.png

 

 

PCSPI, PCNSCx3,PCNSEx4,, PCSAE,PCDRA

Hi @Alejandro_Hernandez ,

 

Thank you so much for your reply.

 

In PAN-OS integrated User-ID - Server monitoring.

Iam confused on choosing the type, cause there's no Lunix based or anything about OpenLDAP mentioned on drop down.

Arun_R_0-1707453853155.png

Which one should i choose, 

Please help me in this.

 

Community Team Member

Hi @Arun_R ,

 

Looking at the compatibility matrix I don't think it's supported:

https://docs.paloaltonetworks.com/compatibility-matrix/user-id-agent/which-servers-can-the-user-id-a...

 

Kind regards,

-Kim.

LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 2038 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!