- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-23-2022 05:14 AM
I have a SAML setup where I want to match a specific user name to an agent config in the gateway:
Gateway -> Agent -> Client settings ->
Source User : <username>
OS: Any
Region/IP address: empty
In the SAML authentication profile the username is listed in the Allow List and is authenticated correctly. However, the client errors with "Client config not found". If I set Source User in Agent Client settings to Any, it works and user name show up in both traffic and GP logs.
Documentation says "You must configure group mapping (Device > User Identification > Group Mapping Settings) before you can select users and groups.", but this is only for AD group mapping. How can I match the username in the SAML login in the Agent client setting?
10-10-2022 07:24 AM
Hi @Anbjorn ,
How do you configure the username for the client settings? Are you using "user@domain.com" or "domain\user" format?
If you set source username as any and clients connect and get settings successfully, what format you see for the username in the GlobalProtect logs?
10-12-2022 12:33 AM
Usernames are "user@domain.com" on both logs and configuration.
02-28-2023 09:09 AM
Hi @Anbjorn - did you ever figure this out? I am having a similar issue. I am using SAML and I have an "any" user config which works fine. But I am trying to add a more restrictive config above that one, which contains specific users or groups, and cannot get it to work. All users keep matching the "any" rule.
01-15-2024 08:04 AM
Same here
We are able to supply configuration to SAML groups using cloud identity engine to pull user to group membership.
But we can not supply configuration directly to saml users
Did anyone figure this out ?
We do not have any AD or LDAP for user group matching
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!