<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Prisma Access with CIE in Prisma Access Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-with-cie/m-p/597456#M848</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need your assistance. The problem is that test rule with user group doesn't have any hits. The users generating traffic are definitely part of the group.&lt;/P&gt;
&lt;P&gt;Setup:&lt;/P&gt;
&lt;P&gt;Prisma Access managed from On-prem Panorama.&lt;/P&gt;
&lt;P&gt;CIE with AD sync. Users and groups are visible from CIE dashboard.&lt;/P&gt;
&lt;P&gt;When policy rule configured I can choose from the groups list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, there are no firewalls to verify if I can get user group membership from CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have concern regarding upper and lower case letters in the group name. *(DB article: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sY3lCAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sY3lCAE&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;AD name: CN=WebAccess-Basic,OU=User,OU=myou,OU=ANOTHEROU,DC=ad,DC=MYDC,DC=org,DC=au&lt;/P&gt;
&lt;P&gt;Policy rule name from the drop down list: cn=webaccess-basic,ou=user,ou=myou,ou=anotherou,dc=ad,dc=mydc,dc=org,dc=au&lt;/P&gt;
&lt;P&gt;The only confusing thing is that I'm getting the drop down list from CIE, I can't believe it gives me the wrong format. And if so, then I'll need to make changes to each group I'm going to use through Group Mapping setting in Prisma device group, right?&lt;/P&gt;
&lt;P&gt;I've attached some screenshots with configuration/settings for reference.&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 01:31:09 GMT</pubDate>
    <dc:creator>pavel.zemtsov</dc:creator>
    <dc:date>2024-09-11T01:31:09Z</dc:date>
    <item>
      <title>Prisma Access with CIE</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-with-cie/m-p/597456#M848</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need your assistance. The problem is that test rule with user group doesn't have any hits. The users generating traffic are definitely part of the group.&lt;/P&gt;
&lt;P&gt;Setup:&lt;/P&gt;
&lt;P&gt;Prisma Access managed from On-prem Panorama.&lt;/P&gt;
&lt;P&gt;CIE with AD sync. Users and groups are visible from CIE dashboard.&lt;/P&gt;
&lt;P&gt;When policy rule configured I can choose from the groups list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, there are no firewalls to verify if I can get user group membership from CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have concern regarding upper and lower case letters in the group name. *(DB article: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sY3lCAE" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sY3lCAE&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;AD name: CN=WebAccess-Basic,OU=User,OU=myou,OU=ANOTHEROU,DC=ad,DC=MYDC,DC=org,DC=au&lt;/P&gt;
&lt;P&gt;Policy rule name from the drop down list: cn=webaccess-basic,ou=user,ou=myou,ou=anotherou,dc=ad,dc=mydc,dc=org,dc=au&lt;/P&gt;
&lt;P&gt;The only confusing thing is that I'm getting the drop down list from CIE, I can't believe it gives me the wrong format. And if so, then I'll need to make changes to each group I'm going to use through Group Mapping setting in Prisma device group, right?&lt;/P&gt;
&lt;P&gt;I've attached some screenshots with configuration/settings for reference.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 01:31:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-with-cie/m-p/597456#M848</guid>
      <dc:creator>pavel.zemtsov</dc:creator>
      <dc:date>2024-09-11T01:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Prisma Access with CIE</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-with-cie/m-p/597907#M856</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1046353903"&gt;@pavel.zemtsov&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Need your assistance. The problem is that test rule with user group doesn't have any hits. The users generating traffic are definitely part of the group.&lt;/P&gt;
&lt;P&gt;Setup:&lt;/P&gt;
&lt;P&gt;Prisma Access managed from On-prem Panorama.&lt;/P&gt;
&lt;P&gt;CIE with AD sync. Users and groups are visible from CIE dashboard.&lt;/P&gt;
&lt;P&gt;When policy rule configured I can choose from the groups list.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unfortunately, there are no firewalls to verify if I can get user group membership from CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have concern regarding upper and lower case letters in the group name. *(DB article: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sY3lCAE" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sY3lCAE&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;AD name: CN=WebAccess-Basic,OU=User,OU=myou,OU=ANOTHEROU,DC=ad,DC=MYDC,DC=org,DC=au&lt;/P&gt;
&lt;P&gt;Policy rule name from the drop down list: cn=webaccess-basic,ou=user,ou=myou,ou=anotherou,dc=ad,dc=mydc,dc=org,dc=au&lt;/P&gt;
&lt;P&gt;The only confusing thing is that I'm getting the drop down list from CIE, I can't believe it gives me the wrong format. And if so, then I'll need to make changes to each group I'm going to use through Group Mapping setting in Prisma device group, right?&lt;/P&gt;
&lt;P&gt;I've attached some screenshots with configuration/settings for reference.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/1046353903"&gt;@pavel.zemtsov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You said the Test Rule with the user group doesn't have any hits and assuming that it doesn't have any spaces and all are lower cases when it auto-populates&lt;BR /&gt;in the firewall policies.&lt;/P&gt;
&lt;P&gt;It has to be all lower case on the firewall.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Additionally You may also please refer the documentation below on how CIE populates the group names in the Security Policies.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-access/3-2/prisma-access-panorama-admin/configure-user-based-policies-with-prisma-access/retrieve-user-id-information/retrieve-group-mapping-using-the-cloud-identity-engine#ida3d63c52-cc40-4553-af7d-f5f88bbdd95a" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-access/3-2/prisma-access-panorama-admin/configure-user-based-policies-with-prisma-access/retrieve-user-id-information/retrieve-group-mapping-using-the-cloud-identity-engine#ida3d63c52-cc40-4553-af7d-f5f88bbdd95a&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If your group info is auto-populates in the Firewall policies with all lowercases and no spaces and still it is not working I would recommend you to raise a support case to further to diagnose the exact causes why it's occurring.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2024 16:03:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-access-discussions/prisma-access-with-cie/m-p/597907#M856</guid>
      <dc:creator>uthankappanpi</dc:creator>
      <dc:date>2024-09-16T16:03:09Z</dc:date>
    </item>
  </channel>
</rss>

