Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Agent Client Settings user name match when SAML

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Agent Client Settings user name match when SAML

L1 Bithead

I have a SAML setup where I want to match a specific user name to an agent config in the gateway:

Gateway -> Agent -> Client settings ->

Source User : <username>

OS: Any

Region/IP address: empty

 

In the SAML authentication profile the username is listed in the Allow List and is authenticated correctly. However, the client errors with "Client config not found". If I set Source User in Agent Client settings to Any, it works and user name show up in both traffic and GP logs.

 

Documentation says "You must configure group mapping (Device > User Identification > Group Mapping Settings) before you can select users and groups.", but this is only for AD group mapping. How can I match the username in the SAML login in the Agent client setting?

 

 

4 REPLIES 4

Hi @Anbjorn ,

How do you configure the username for the client settings? Are you using "user@domain.com" or "domain\user" format?

If you set source username as any and clients connect and get settings successfully, what format you see for the username in the GlobalProtect logs?

L1 Bithead

Usernames are "user@domain.com" on both logs and configuration.

L1 Bithead

Hi @Anbjorn - did you ever figure this out?  I am having a similar issue.  I am using SAML and I have an "any" user config which works fine.  But I am trying to add a more restrictive config above that one, which contains specific users or groups, and cannot get it to work. All users keep matching the "any" rule.

L1 Bithead

Same here

We are able to supply configuration to SAML groups using cloud identity engine to pull user to group membership.

But we can not supply configuration directly to saml users

Did anyone figure this out ? 

We do not have any AD or LDAP for user group matching 

  • 2325 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!