- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-08-2021 02:06 AM
Restriction of the users on the GP portal page.
We selected a particular group in the allowed list, but authentication was failing unless we select all.
06-08-2021 08:51 AM
probably domain info wrong, post auth profile so we can check
06-08-2021 09:05 AM
When you do not select all, what is showing up in the logs?
Also, how are the users defined? You mentioned groups? please provide more info on the auth method/etc.
06-09-2021 05:05 AM
My Actual Issue,
GlobalProtect Portal or Agent users fail authentication
My Authentication Profile has specific filtered groups. The users appear to be in the group that makes up the allow list. However, the message "user not in allow list" still appears. If the allow list is changed to have "all" rather than specific groups, the user authenticates fine.
And I followed this link https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClizCAC
Model 850, VSYS Not Support, so I skip the "shared" authentication profile here.
06-09-2021 07:17 AM
Have you run the command "show user group name [name of your group]"
if you did, do the users have the domain name included "domain\username"
if 'yes' then have you added that domain name to the authentication profile.
06-09-2021 10:12 PM
Yes.. ran the command to show the user group name and added it to the auth profile as it was.
then ran a test auth user & pass from CLI.. the Authentication failed with the user not allowed in the list.
06-10-2021 12:43 AM - edited 06-10-2021 12:52 AM
when you run a cli auth profile test you need to use domain\username because cli test does not use the domain info in the auth profile. it just ignores it.
also you need to ensure you have the correct setting samaccountname or userprincipalname in both group mapping and the auth profile.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!