<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID (with Windows Agent) not working in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533303#M981</link>
    <description>&lt;P&gt;Ah, thank you!&lt;BR /&gt;I already got this hint.&amp;nbsp;&lt;BR /&gt;This brought me to a next issue - I can not add groups as the firewall can not read the DC. There is just no group in the list to add. (it seems reachable in general, if I shut it off I get a real error).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FloriReus_0-1678094945648.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48476iC0529BEFBB312E49/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="FloriReus_0-1678094945648.png" alt="FloriReus_0-1678094945648.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Mar 2023 09:31:57 GMT</pubDate>
    <dc:creator>FloriReus</dc:creator>
    <dc:date>2023-03-06T09:31:57Z</dc:date>
    <item>
      <title>User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/532889#M968</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;we set up User ID based on these docs:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-mapping-using-the-windows-user-id-agent&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Konfiguration and installation is working:&lt;/P&gt;
&lt;P&gt;- the agent installed on server 2019 DC is getting infos&lt;/P&gt;
&lt;P&gt;- the firewall (PA-220 9.1) is getting infos from the agent&lt;/P&gt;
&lt;P&gt;- the users are displayed in monitoring&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but:&lt;/P&gt;
&lt;P&gt;- we can not select users in security policies&lt;/P&gt;
&lt;P&gt;- we can manually add users in the policies - then the policies never matches.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 07:28:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/532889#M968</guid>
      <dc:creator>FloriReus</dc:creator>
      <dc:date>2023-03-02T07:28:34Z</dc:date>
    </item>
    <item>
      <title>Re: User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533207#M978</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239497"&gt;@FloriReus&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;based on what you described, the only thing coming to my mind is missing inclusion of "Domain Users" group under: Device &amp;gt; User Identification &amp;gt; Group Mapping &amp;gt; [Name] &amp;gt; Group Include List &amp;gt; add: "Domain Name\Domain Users". This should cover all AD users. Could you make sure this is in the place?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 21:24:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533207#M978</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-03-03T21:24:26Z</dc:date>
    </item>
    <item>
      <title>Re: User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533222#M979</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239497"&gt;@FloriReus&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The security policy drop down only shows groups.&amp;nbsp; You need to manually type in users.&amp;nbsp; &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXWCA0" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXWCA0&lt;/A&gt;&amp;nbsp; (It will also show previously typed in users.)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you add the user in the security policy exactly how you see it in the Monitoring tab, lan\user1, and let us know if that works?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Sat, 04 Mar 2023 04:12:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533222#M979</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2023-03-04T04:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533303#M981</link>
      <description>&lt;P&gt;Ah, thank you!&lt;BR /&gt;I already got this hint.&amp;nbsp;&lt;BR /&gt;This brought me to a next issue - I can not add groups as the firewall can not read the DC. There is just no group in the list to add. (it seems reachable in general, if I shut it off I get a real error).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FloriReus_0-1678094945648.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48476iC0529BEFBB312E49/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="FloriReus_0-1678094945648.png" alt="FloriReus_0-1678094945648.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 09:31:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533303#M981</guid>
      <dc:creator>FloriReus</dc:creator>
      <dc:date>2023-03-06T09:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533305#M982</link>
      <description>&lt;P&gt;I tried this already (see attached screenshots). seems not top work.&amp;nbsp;&lt;BR /&gt;but thanks for the link!&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 09:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533305#M982</guid>
      <dc:creator>FloriReus</dc:creator>
      <dc:date>2023-03-06T09:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533323#M983</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239497"&gt;@FloriReus&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To make sure there is no mis-understanding please replace: "&lt;SPAN&gt;Domain Name&lt;/SPAN&gt;" with your organization's real AD domain name.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding the issue you described, when you configure LDAP profile under: Device &amp;gt; Server Profiles &amp;gt; LDAP &amp;gt; [LDAP Profile Name], make sure that under Server Settings you configure Base DN that covers your entire domain. You can find that information from Windows CMD by issuing: dsquery *&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Base DN is first returned entry on the top.&amp;nbsp;The Base DN is the starting point an LDAP server uses when searching for users authentication within your Active Directory and if this is configured correctly this is what you will see under "Available Groups" in Group Mapping Settings. You should be able to type AD group name and press search button, then "+" button to add it to include list:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PavelK_0-1678104287489.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48479iBD8FD96B70CA7203/image-size/large?v=v2&amp;amp;px=999" role="button" title="PavelK_0-1678104287489.png" alt="PavelK_0-1678104287489.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 12:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533323#M983</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-03-06T12:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533325#M984</link>
      <description>&lt;P&gt;yes, you are right!&lt;BR /&gt;I missed the baseDN; now it's working!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FloriReus_0-1678104972360.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/48480i25959C14017081C2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="FloriReus_0-1678104972360.png" alt="FloriReus_0-1678104972360.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Mar 2023 12:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533325#M984</guid>
      <dc:creator>FloriReus</dc:creator>
      <dc:date>2023-03-06T12:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: User ID (with Windows Agent) not working</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533406#M989</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239497"&gt;@FloriReus&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for getting back to me. Based on your screen shot, there are 2 additional things I would suggest:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- Enable LDAPS by selecting: "Require SSL/TLS secured connection" if possible to secure LDAP traffic.&lt;/P&gt;
&lt;P&gt;- Add an additional LDAP server for redundancy to avoid single point of failure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 04:27:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-with-windows-agent-not-working/m-p/533406#M989</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-03-07T04:27:28Z</dc:date>
    </item>
  </channel>
</rss>

