How to configure both Authentication Local User and AD user to access GlobalProtect in PaloAlto

Q: Currently, we are using a local user database to access GloablProtect in PA 850 firewall. We are migrating Local user database to AD user database. We have created two Authentications, one for Local user and another for AD user. only the top is working.

Can we have both Authentication Local User and AD user to access GlobalProtect? If so, how do you make them work?

A: Yes, you can use Authentication Sequence, where you enter all Authentication profiles to be use for login. Go to Device > Authentication sequence.

Create new sequence and select all needed profiles and use this sequence-entry in GP (Portal/Gateway).

Published by

Bob Lin

Bob Lin, Chicagotech-MVP, MCSE & CNE Data recovery, Windows OS Recovery, Networking, and Computer Troubleshooting on http://www.ChicagoTech.net How to Install and Configure Windows, VMware, Virtualization and Cisco on http://www.HowToNetworking.com