09-23-2022 05:14 AM
I have a SAML setup where I want to match a specific user name to an agent config in the gateway:
Gateway -> Agent -> Client settings ->
Source User : <username>
OS: Any
Region/IP address: empty
In the SAML authentication profile the username is listed in the Allow List and is authenticated correctly. However, the client errors with "Client config not found". If I set Source User in Agent Client settings to Any, it works and user name show up in both traffic and GP logs.
Documentation says "You must configure group mapping (Device > User Identification > Group Mapping Settings) before you can select users and groups.", but this is only for AD group mapping. How can I match the username in the SAML login in the Agent client setting?
10-10-2022 07:24 AM
Hi @Anbjorn ,
How do you configure the username for the client settings? Are you using "user@domain.com" or "domain\user" format?
If you set source username as any and clients connect and get settings successfully, what format you see for the username in the GlobalProtect logs?
10-12-2022 12:33 AM
Usernames are "user@domain.com" on both logs and configuration.
02-28-2023 09:09 AM
Hi @Anbjorn - did you ever figure this out? I am having a similar issue. I am using SAML and I have an "any" user config which works fine. But I am trying to add a more restrictive config above that one, which contains specific users or groups, and cannot get it to work. All users keep matching the "any" rule.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!