<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID to be used in security policy - FW not offering user/group list in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550907#M1577</link>
    <description>&lt;P&gt;Hello Szi7443,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you doing the configuration from Panorama or the firewall?&lt;/P&gt;
&lt;P&gt;On the firewall, do you see the groups when you try to configure the user/groups?&lt;/P&gt;
&lt;P&gt;If yes, that’s ok.&lt;/P&gt;
&lt;P&gt;If not, review the config on the firewall, on CLI you can look for the group list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you are having the issue on Panorama.&lt;/P&gt;
&lt;P&gt;- do the check on the firewall&lt;/P&gt;
&lt;P&gt;if Firewall OK, make sure the device group has master device defined. This firewall will send the group mapping to Panorama.&lt;/P&gt;
&lt;P&gt;if fw not ok, investigate on firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jul 2023 12:57:09 GMT</pubDate>
    <dc:creator>ozheng</dc:creator>
    <dc:date>2023-07-25T12:57:09Z</dc:date>
    <item>
      <title>UserID to be used in security policy - FW not offering user/group list</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550177#M1548</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have problem with User-ID not being selectable when creating/editing security policy rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Setup is as followed:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;branch firewalls connected to Panorama&lt;/LI&gt;
&lt;LI&gt;Firewall 3400 with 10.2.4 software&lt;/LI&gt;
&lt;LI&gt;LDAP server configured&lt;/LI&gt;
&lt;LI&gt;Authentication profile configured&lt;/LI&gt;
&lt;LI&gt;Included groups in "user identification" configured&lt;/LI&gt;
&lt;LI&gt;User-ID configured (i am seeing domain\username in traffic log)&lt;/LI&gt;
&lt;LI&gt;On zones in question, I have user-id enabled&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Command &lt;EM&gt; show user group-mapping state &amp;lt;included group name&amp;gt; &lt;/EM&gt;shows no errors connecting to LDAP. Command show user group name domain\groupname shows members of the group.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So with given being displayed and working, I would say that there's no obstacle in configuring usernames groups in the security policy rules. Yet I can't figure out why firewall is not offering me group drop-down and when I fill in domain\groupname to "source user", that AD group or user gets black background which as per my understanding indicates that user or group weren't found.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance for any hints.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 14:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550177#M1548</guid>
      <dc:creator>szi7443</dc:creator>
      <dc:date>2023-07-20T14:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: UserID to be used in security policy - FW not offering user/group list</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550182#M1549</link>
      <description>&lt;P&gt;Edit: It looks like all is working well. I have created a rule on position let's say 10 that contains 1 user called X (the background is black with red letters). Rule 11 is much more broader rule where internet access of user X would be taken care of if user X would not be taken care of by rule 10. The hit count is rising also for rule 10. &lt;BR /&gt;&lt;BR /&gt;So it seems that all is configured well, it only puzzled me that with every demo I saw on this topic, the presenter has list of users / groups in "select user" dropdown &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 15:28:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550182#M1549</guid>
      <dc:creator>szi7443</dc:creator>
      <dc:date>2023-07-20T15:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: UserID to be used in security policy - FW not offering user/group list</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550191#M1550</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/304674"&gt;@szi7443&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is very interesting!&amp;nbsp; I am running 10.2.4-h2 and my groups show up under Source User when I click Add.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have never encountered the black background.&amp;nbsp; There have been times (e.g., Panorama) where the dropdown was not available, and I pasted the group in.&amp;nbsp; It worked fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2023 15:35:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550191#M1550</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-07-20T15:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: UserID to be used in security policy - FW not offering user/group list</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550907#M1577</link>
      <description>&lt;P&gt;Hello Szi7443,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you doing the configuration from Panorama or the firewall?&lt;/P&gt;
&lt;P&gt;On the firewall, do you see the groups when you try to configure the user/groups?&lt;/P&gt;
&lt;P&gt;If yes, that’s ok.&lt;/P&gt;
&lt;P&gt;If not, review the config on the firewall, on CLI you can look for the group list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you are having the issue on Panorama.&lt;/P&gt;
&lt;P&gt;- do the check on the firewall&lt;/P&gt;
&lt;P&gt;if Firewall OK, make sure the device group has master device defined. This firewall will send the group mapping to Panorama.&lt;/P&gt;
&lt;P&gt;if fw not ok, investigate on firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2023 12:57:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/550907#M1577</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-07-25T12:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: UserID to be used in security policy - FW not offering user/group list</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/551091#M1583</link>
      <description>&lt;P&gt;Hi, I am configuring everything form Panorama.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not aware of what you mean exactly with "on the firewall". If I SSH to the firewall, I can see the user-id mappings and members of the groups retrieved from AD with commands like:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;show user group name domain\group_name&lt;/LI&gt;
&lt;LI&gt;show user ip-user-mapping all&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The thing is that Panorama is not providing me the values in dropdown when configuring a firewall rule. The original issue can be considered as solved. However, I would still ask two things: &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;When configuring user-id, it did not work for me without an authentication profile. Did I misunderstand something or that auth profile is indeed useless for user-id?&lt;/LI&gt;
&lt;LI&gt;When configuring an application in firewall rule, some of the apps have red gear icon - what does that mean?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 13:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/551091#M1583</guid>
      <dc:creator>szi7443</dc:creator>
      <dc:date>2023-07-26T13:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: UserID to be used in security policy - FW not offering user/group list</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/551100#M1585</link>
      <description>&lt;P&gt;Panorama is not pulling directly the mapping, it is a firewall doing that.&lt;/P&gt;
&lt;P&gt;So if you want to have the group on Panorama, Panorama needs to pull it from a Device (you can search for "User-ID Panorama Master Device".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authentication Profile? If you set up a captive portal that is the only use case with authentication profile.&lt;/P&gt;
&lt;P&gt;Red gear icon, I would suspect there is an override somewhere..&lt;BR /&gt;Anyway, if you want to discuss more about it, better open a new discussion and profile at least a screenshot or you can also open a case to TAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Olivier&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2023 14:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/userid-to-be-used-in-security-policy-fw-not-offering-user-group/m-p/551100#M1585</guid>
      <dc:creator>ozheng</dc:creator>
      <dc:date>2023-07-26T14:30:50Z</dc:date>
    </item>
  </channel>
</rss>

