How to match the GlobalProtect Portal or Gateway agent configuration by email username with CIE?

How to match the GlobalProtect Portal or Gateway agent configuration by email username with CIE?

2716
Created On 08/30/22 22:19 PM - Last Modified 06/06/25 20:08 PM


Objective


This article provides instructions to match the GlobalProtect agent configuration using Distinguished Name or Email Address (User Principal Name or UPN).



Environment


  • Palo Alto Firewalls
  • Supported PAN-OS versions
  • GlobalProtect Portal
  • GlobalProtect Gateway
  • GlobalProtect App
  • Cloud Identity Engine (CIE)


Procedure


  1. Navigate to Device > User Identification > Cloud Identity Engine and edit the following settings:
    1. Within User Attributes tab, change Primary Username field to "User Principal Name" and E-Mail field to "Mail".
      Screen Shot 2022-08-30 at 3.06.09 PM.png
    2. Within Group Attributes tab, Group Name field can be set to either to "Distinguished Name" (DN) or "Name". Make sure the user group name in the security policy matches the group attribute format.
      Screen Shot 2022-08-30 at 3.05.56 PM.png
    3. Add the email username or DN user group to the GP Portal or Gateway agent configuration.
      Agent-Config 


Additional Information


The user group list and user-to-group information can be checked using the following commands.
admin@PANOS-FW> show user group list
cn=vpn-users,dc=khanit,dc=tech
Total: 1
* : Custom Group

admin@PANOSFW> show user group name “cn=vpn-users,dc=khanit,dc=tech”
source type: cloud
Group type: Directory Sync Service
[1     ] sahan@khanit.tech
[2     ] sraque@khanit.tech
[3     ] admin123@khanit.tech
Note: In order to view the CIE groups on the firewall's CLI, those groups need to be referenced in the security policy via GUI and perform a commit.


Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wlRPCAY&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language