<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Master User-id device receives non-functioning configuration for userID Group Include list from Panorama in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-user-id-device-receives-non-functioning-configuration-for/m-p/482818#M858</link>
    <description>&lt;P&gt;I have a User-Id configuration that has been working successfully for 6 months.&amp;nbsp; I went to add a new group to the group include list, and the syntax that was written from Panorama had JUST the group name in this form :domain\group_name.&amp;nbsp; The working groups as listed by running the '&lt;SPAN&gt;show config merged | match group-include-list' all have a syntax similar to this: [cn=group_name, ou=users and groups, ou=yyy, dc=my_domain, dc=com] etc etc . the FW does not recognize the new group, and cannot retrieve any of the users, so it is non-functional.&amp;nbsp; the previously working groups still work.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; FYI: the groups show up correctly when I browse the dialog in Panorama - but none of them, even the working ones, display the cn-ou-dc parameters.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama 9.1.12-h3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pa-VM100 9.1.0-h3&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 26 Apr 2022 22:10:50 GMT</pubDate>
    <dc:creator>ClaytonHuml</dc:creator>
    <dc:date>2022-04-26T22:10:50Z</dc:date>
    <item>
      <title>Master User-id device receives non-functioning configuration for userID Group Include list from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-user-id-device-receives-non-functioning-configuration-for/m-p/482818#M858</link>
      <description>&lt;P&gt;I have a User-Id configuration that has been working successfully for 6 months.&amp;nbsp; I went to add a new group to the group include list, and the syntax that was written from Panorama had JUST the group name in this form :domain\group_name.&amp;nbsp; The working groups as listed by running the '&lt;SPAN&gt;show config merged | match group-include-list' all have a syntax similar to this: [cn=group_name, ou=users and groups, ou=yyy, dc=my_domain, dc=com] etc etc . the FW does not recognize the new group, and cannot retrieve any of the users, so it is non-functional.&amp;nbsp; the previously working groups still work.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt; FYI: the groups show up correctly when I browse the dialog in Panorama - but none of them, even the working ones, display the cn-ou-dc parameters.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Panorama 9.1.12-h3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Pa-VM100 9.1.0-h3&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 22:10:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/master-user-id-device-receives-non-functioning-configuration-for/m-p/482818#M858</guid>
      <dc:creator>ClaytonHuml</dc:creator>
      <dc:date>2022-04-26T22:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Master User-id device receives non-functioning configuration for userID Group Include list from Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/master-user-id-device-receives-non-functioning-configuration-for/m-p/482937#M859</link>
      <description>&lt;P&gt;Thank you for the post&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/144784"&gt;@ClaytonHuml&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you want to add a new AD group into include list from Panorama, you have to configure AD group with whole LDAP string. Here is corresponding KB:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIOCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIOCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;After this is pushed to managed Firewall, you will see AD group in this format:&amp;nbsp;domain\group_name on Firewall side.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2022 22:32:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/master-user-id-device-receives-non-functioning-configuration-for/m-p/482937#M859</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2022-04-26T22:32:16Z</dc:date>
    </item>
  </channel>
</rss>

