<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID group mapping, not pulling groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-not-pulling-groups/m-p/499710#M105196</link>
    <description>&lt;P&gt;Server monitoring is not the same thing as group mapping. You need to configure a group mapping config under the "Group Mapping" tab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once configured, you can start with the following command to check the actual status. It might be that there's an issue connecting to the server on LDAP or something.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; show user group-mapping state all&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The useridd log will contain the actual connection attempts to LDAP/LDAPS.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; less mp-log useridd.log&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you already have a group mapping configured, are you able to browse your LDAP tree from the GUI under your group mapping config -&amp;gt; group include list? If not, you likely have connectivity or authentication issues to LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the firewall is actually connecting and you still see 0 groups, you might have the base dn in your LDAP profile set incorrectly. You need to set this either at the root, or to somewhere which is in between the root and where the users and groups are both configured.&lt;/P&gt;</description>
    <pubDate>Sun, 05 Jun 2022 15:50:26 GMT</pubDate>
    <dc:creator>dmifsud</dc:creator>
    <dc:date>2022-06-05T15:50:26Z</dc:date>
    <item>
      <title>User ID group mapping, not pulling groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-not-pulling-groups/m-p/499632#M105188</link>
      <description>&lt;P&gt;I have a problem, I'm&amp;nbsp; setting the user ID group mapping, I can pull users, but not groups, I see 0 groups, I restarted the service, no luck, I verified all server monitoring is connected, and traffic is going to DC'd, the PAN-OS is 10.1.5, I have a similar setup in a pair of firewalls that are on pan-os 9.1.13 with no issues, any advice that points me in the right direction is greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 01:59:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-not-pulling-groups/m-p/499632#M105188</guid>
      <dc:creator>HSi-Salem</dc:creator>
      <dc:date>2022-06-05T01:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: User ID group mapping, not pulling groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-not-pulling-groups/m-p/499710#M105196</link>
      <description>&lt;P&gt;Server monitoring is not the same thing as group mapping. You need to configure a group mapping config under the "Group Mapping" tab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once configured, you can start with the following command to check the actual status. It might be that there's an issue connecting to the server on LDAP or something.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; show user group-mapping state all&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The useridd log will contain the actual connection attempts to LDAP/LDAPS.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; less mp-log useridd.log&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you already have a group mapping configured, are you able to browse your LDAP tree from the GUI under your group mapping config -&amp;gt; group include list? If not, you likely have connectivity or authentication issues to LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the firewall is actually connecting and you still see 0 groups, you might have the base dn in your LDAP profile set incorrectly. You need to set this either at the root, or to somewhere which is in between the root and where the users and groups are both configured.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jun 2022 15:50:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-not-pulling-groups/m-p/499710#M105196</guid>
      <dc:creator>dmifsud</dc:creator>
      <dc:date>2022-06-05T15:50:26Z</dc:date>
    </item>
    <item>
      <title>Re: User ID group mapping, not pulling groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-not-pulling-groups/m-p/588409#M117314</link>
      <description>&lt;P&gt;The fix it to include the entire path eg., cn=xxxx instead of domain\groupname and that should include the groups.&lt;/P&gt;</description>
      <pubDate>Thu, 30 May 2024 14:59:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-not-pulling-groups/m-p/588409#M117314</guid>
      <dc:creator>m-lobo</dc:creator>
      <dc:date>2024-05-30T14:59:04Z</dc:date>
    </item>
  </channel>
</rss>

