Global Protect portal page error

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Global Protect portal page error

L4 Transporter

Restriction of the users on the GP portal page.

We selected a particular group in the allowed list, but authentication was failing unless we select all.

6 REPLIES 6

L7 Applicator

probably domain info wrong, post auth profile so we can check

L7 Applicator

When you do not select all, what is showing up in the logs? 

Also, how are the users defined? You mentioned groups? please provide more info on the auth method/etc.

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!

My Actual Issue,

 

GlobalProtect Portal or Agent users fail authentication

My Authentication Profile has specific filtered groups. The users appear to be in the group that makes up the allow list. However, the message "user not in allow list" still appears. If the allow list is changed to have "all" rather than specific groups, the user authenticates fine.

 

And I followed this link https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC

 

Model 850, VSYS Not Support, so I skip the "shared" authentication profile here.

Have you run the command   "show user group name  [name of your group]"

if you did, do the users have the domain name included  "domain\username"

 

if 'yes' then have you added that domain name to the authentication profile.

 

 

Yes.. ran the command to show the user group name and added it to the auth profile as it was.

then ran a test auth user & pass from CLI.. the Authentication failed with the user not allowed in the list.

when you run a cli auth profile test you need to use domain\username  because cli test does not use the domain info in the auth profile. it just ignores it.

 

also you need to ensure you have the correct setting samaccountname or userprincipalname in both group mapping and the auth profile.

 

 

  • 3896 Views
  • 6 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!