<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Groups added to VPN in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/groups-added-to-vpn/m-p/502907#M2855</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can add groups, but you need to make sure the group has been pulled via your group-mapping config, and that the user is in that group in the right format.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Verify with the following commands that:&lt;/P&gt;&lt;P&gt;- The group is pulled by group-mapping&lt;/P&gt;&lt;P&gt;- The user is listed as being in that group on the firewall&lt;/P&gt;&lt;P&gt;- The username format format in the IP mapping matches the format of the use listed in that group, or matches an attribute for that user&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; show user group-mapping state all
&amp;gt; show user group name &amp;lt;group name&amp;gt;
&amp;gt; show user ip-user-mapping ip &amp;lt;gp IP while connected&amp;gt;
&amp;gt; show user user-attributes user &amp;lt;username&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's possible that there's a domain mismatch which often happens. Make sure that you have a domain map as well:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFn" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFn&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jun 2022 11:03:17 GMT</pubDate>
    <dc:creator>dmifsud</dc:creator>
    <dc:date>2022-06-11T11:03:17Z</dc:date>
    <item>
      <title>Groups added to VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/groups-added-to-vpn/m-p/502623#M2853</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have Global Protect setup and people are able to connect via a VPN connection with Split Tunnel turned on.&lt;BR /&gt;I have a request to setup another config for a certain group in AD that would give this group of users a different IP and&amp;nbsp; have Split Tunneling turned off forcing all traffic over the VPN.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have this setup and working. If I put myself in the client settings in the config I get the correct IP and all my traffic goes over the VPN connection but if I place the group in the list it does not get applied to the user in the group.&lt;/P&gt;&lt;P&gt;My question is it possible to add groups to this or does it have to be the individual user.&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="thoffman_0-1654866175790.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/41702i90ABF84837BD2215/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="thoffman_0-1654866175790.png" alt="thoffman_0-1654866175790.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 13:03:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/groups-added-to-vpn/m-p/502623#M2853</guid>
      <dc:creator>thoffman</dc:creator>
      <dc:date>2022-06-10T13:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Groups added to VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/groups-added-to-vpn/m-p/502907#M2855</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can add groups, but you need to make sure the group has been pulled via your group-mapping config, and that the user is in that group in the right format.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Verify with the following commands that:&lt;/P&gt;&lt;P&gt;- The group is pulled by group-mapping&lt;/P&gt;&lt;P&gt;- The user is listed as being in that group on the firewall&lt;/P&gt;&lt;P&gt;- The username format format in the IP mapping matches the format of the use listed in that group, or matches an attribute for that user&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; show user group-mapping state all
&amp;gt; show user group name &amp;lt;group name&amp;gt;
&amp;gt; show user ip-user-mapping ip &amp;lt;gp IP while connected&amp;gt;
&amp;gt; show user user-attributes user &amp;lt;username&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's possible that there's a domain mismatch which often happens. Make sure that you have a domain map as well:&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFn" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFn&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jun 2022 11:03:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/groups-added-to-vpn/m-p/502907#M2855</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2022-06-11T11:03:17Z</dc:date>
    </item>
    <item>
      <title>Re: Groups added to VPN</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/groups-added-to-vpn/m-p/502977#M2858</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/172185"&gt;@thoffman&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Does your group actually have the users listed within it, or does it consist of nested groups? If you're puling the group as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/131231"&gt;@dmifsud&lt;/a&gt;&amp;nbsp;mentioned this should work without issue as long as you aren't trying to use nested groups for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 02:49:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/groups-added-to-vpn/m-p/502977#M2858</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-06-13T02:49:42Z</dc:date>
    </item>
  </channel>
</rss>

