<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to Apply Group based Security Policy in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-group-based-security-policy/m-p/598960#M3815</link>
    <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have successfully integrated LDAP with the Palo Alto firewall, and user-ID mapping via the user-ID agent is functioning as expected. We are able to use LDAP users in the security policy without any issues. However, when attempting to apply LDAP groups to the policy, the policy does not seem to work as intended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have configured the group mapping correctly, and when we check the user list within the group via CLI, it displays accurately.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please assist us with your expertise to resolve this issue.&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2024 11:58:19 GMT</pubDate>
    <dc:creator>Mebinbaby</dc:creator>
    <dc:date>2024-09-27T11:58:19Z</dc:date>
    <item>
      <title>Unable to Apply Group based Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-group-based-security-policy/m-p/598960#M3815</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have successfully integrated LDAP with the Palo Alto firewall, and user-ID mapping via the user-ID agent is functioning as expected. We are able to use LDAP users in the security policy without any issues. However, when attempting to apply LDAP groups to the policy, the policy does not seem to work as intended.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have configured the group mapping correctly, and when we check the user list within the group via CLI, it displays accurately.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please assist us with your expertise to resolve this issue.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 11:58:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-group-based-security-policy/m-p/598960#M3815</guid>
      <dc:creator>Mebinbaby</dc:creator>
      <dc:date>2024-09-27T11:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Apply Group based Security Policy</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-group-based-security-policy/m-p/598970#M3816</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/747125303"&gt;@Mebinbaby&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The most common reason, by far, for group mappings not to work is that the format of the user name in the IP mapping is different from the format of the username in the group mapping.&amp;nbsp; The username must match exactly.&amp;nbsp; You can run the following commands to verify the format is exactly the same:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; show user ip-user-mapping all
&amp;gt; show user group list
&amp;gt; show user group name "cn=it_operations,cn=users,dc=al,dc=com"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Obviously, replace the group name above with the one in question.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&amp;nbsp; If there are spaces in the group name, it must be in quotes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the formats are different, please post and we can look at resolving it.&amp;nbsp; Please also post the source of the User/IP mappings.&amp;nbsp; If the source involves an authentication profile, please post the type.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 13:06:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-apply-group-based-security-policy/m-p/598970#M3816</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-09-27T13:06:10Z</dc:date>
    </item>
  </channel>
</rss>

