How to permit GP access with two different domains?

Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to permit GP access with two different domains?

L2 Linker

Hello all,


I'm setting up a second authentication domain in GP but I'm not successful trying to authenticate.


The domain DC=domain1,DC=br,DC=local works normally.

The new domain DC=domain999,DC=local does not work. When I try to authenticate through it I see in the logs that it failed but it recognized the domain and the IP of the AD.


This new domain I configured in: Device>Server Profiles>LDAP.

Then on: Device>Server Profiles>User Identification>Group Mapping Settings

Then on:Network>GP>Portals>"vpn_portal">Agent>^vpn_agent">User/User Group

Then on:Network>GP>Gateways>"vpn_gtw">Agent>Client Settings


When I insert domain999.local/, my authentication failure and generate these logs:





Cyber Elite
Cyber Elite


Did you update your authentication profile to actually include the new LDAP server profile? It doesn't look like you did, so that new LDAP server profile isn't actually being used. The initial auth-fail message you have in your picture is what you need to correct before going any further.

Hi BPry,

My Authentication Profile before this configuration had local
authentication and an LDAP. Now, in addition to this same configuration, it
also has the new LDAP.

In the image I showed he is trying to authenticate to the new LDAP.

When I test this same user via CLI, my authentication is successful.



Are you using the username modifier in the auth profile... i only ask as I’m sure this is ignored when using cli.


i would use Monitor/Packet Capture with the ldap server in a filter to see what the palo is sending. It may be adding additional information to the request...

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!