<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove Domain Name from LDAP user mapping IMPOSIBLE =( in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/509164#M105992</link>
    <description>Hi&lt;BR /&gt;&lt;BR /&gt;I receive the user logs from the Pulse Secure VPN appliance to the USER ID&lt;BR /&gt;agent located on windows server&lt;BR /&gt;&lt;BR /&gt;With the regex i was able to just get the user id from the user connected.&lt;BR /&gt;&lt;BR /&gt;My surprise was that I was not unable to map the user id with the domain&lt;BR /&gt;group on security policy, this is really a bad situation for us.&lt;BR /&gt;&lt;BR /&gt;Is it possible to just avoid the domain name on the palo alto when trying&lt;BR /&gt;to search on ldap group?&lt;BR /&gt;I can not understand why yes or yes paloalto build this:&lt;BR /&gt;&lt;BR /&gt;&amp;gt;From LDAP group PaloAlto get:&lt;BR /&gt;domainname\userid&lt;BR /&gt;&lt;BR /&gt;With the UserID agent after the regex i get a mapping with IP+userid, and&lt;BR /&gt;on the firewall logs i can see this way:&lt;BR /&gt;&lt;BR /&gt;source ip: ip from user&lt;BR /&gt;source user: userid&lt;BR /&gt;&lt;BR /&gt;The security policy will never match!! as there is a difference between&lt;BR /&gt;&lt;BR /&gt;domainname\userid =&amp;gt; LDAP PaloAlto&lt;BR /&gt;&lt;BR /&gt;userid =&amp;gt; Information from my agent&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hours and hours spent here and no answer anywhere im totally frustrated ...&lt;BR /&gt;</description>
    <pubDate>Mon, 18 Jul 2022 10:11:38 GMT</pubDate>
    <dc:creator>alvaroarcaz</dc:creator>
    <dc:date>2022-07-18T10:11:38Z</dc:date>
    <item>
      <title>Remove Domain Name from LDAP user mapping IMPOSIBLE =(</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/508983#M105937</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Someone know if there is a way to remove the domain name from the group mapping&lt;/P&gt;
&lt;P&gt;The reason why is because i get from external source on palo alto the user id test1 or "test2" or "test3"&lt;/P&gt;
&lt;P&gt;Goal is create a policy rule base on the source user that is being part of a domain group&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my case LDAP group mapping get this information:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show user group name emea.com\test&lt;/P&gt;
&lt;P&gt;short name: emea.com\test&lt;/P&gt;
&lt;P&gt;source type: ldap&lt;BR /&gt;source: test&lt;/P&gt;
&lt;P&gt;[1 ] emea.com\test1&lt;BR /&gt;[2 ] emea.com\test2&lt;BR /&gt;[3 ] emea.com\test3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is good but only need from the group mapping the name&lt;/P&gt;
&lt;P&gt;"test1" or "test2" or "test3"&lt;/P&gt;
&lt;P&gt;and not&amp;nbsp;&lt;/P&gt;
&lt;P&gt;emea.com\test1&lt;BR /&gt;emea.com\test2&lt;BR /&gt;emea.com\test3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i expend hours and there is no way to understand or found the reason why palo alto get from ldap group mapping "domain name + name"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 17:24:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/508983#M105937</guid>
      <dc:creator>alvaroarcaz</dc:creator>
      <dc:date>2022-07-14T17:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Domain Name from LDAP user mapping IMPOSIBLE =(</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/509062#M105953</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87672"&gt;@alvaroarcaz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;If I am not wrong, group mapping will always add domain, because it needs to cover cases where you have multiple domains or even domain forest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in my humble opinion you should try to append the domain to the user-ip-mapping so it can match the group mapping.&lt;/P&gt;
&lt;P&gt;Can you share bit more information how you receive user-ip-mapping? How it is configured currently?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 10:16:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/509062#M105953</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-07-15T10:16:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Domain Name from LDAP user mapping IMPOSIBLE =(</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/509164#M105992</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;I receive the user logs from the Pulse Secure VPN appliance to the USER ID&lt;BR /&gt;agent located on windows server&lt;BR /&gt;&lt;BR /&gt;With the regex i was able to just get the user id from the user connected.&lt;BR /&gt;&lt;BR /&gt;My surprise was that I was not unable to map the user id with the domain&lt;BR /&gt;group on security policy, this is really a bad situation for us.&lt;BR /&gt;&lt;BR /&gt;Is it possible to just avoid the domain name on the palo alto when trying&lt;BR /&gt;to search on ldap group?&lt;BR /&gt;I can not understand why yes or yes paloalto build this:&lt;BR /&gt;&lt;BR /&gt;&amp;gt;From LDAP group PaloAlto get:&lt;BR /&gt;domainname\userid&lt;BR /&gt;&lt;BR /&gt;With the UserID agent after the regex i get a mapping with IP+userid, and&lt;BR /&gt;on the firewall logs i can see this way:&lt;BR /&gt;&lt;BR /&gt;source ip: ip from user&lt;BR /&gt;source user: userid&lt;BR /&gt;&lt;BR /&gt;The security policy will never match!! as there is a difference between&lt;BR /&gt;&lt;BR /&gt;domainname\userid =&amp;gt; LDAP PaloAlto&lt;BR /&gt;&lt;BR /&gt;userid =&amp;gt; Information from my agent&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Hours and hours spent here and no answer anywhere im totally frustrated ...&lt;BR /&gt;</description>
      <pubDate>Mon, 18 Jul 2022 10:11:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/509164#M105992</guid>
      <dc:creator>alvaroarcaz</dc:creator>
      <dc:date>2022-07-18T10:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Domain Name from LDAP user mapping IMPOSIBLE =(</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/511208#M106290</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/87672"&gt;@alvaroarcaz&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I know there is a way to override the domain for Group Mapping, but not sure if there is a way to remove it completely.&lt;/P&gt;
&lt;P&gt;As I mentioned for me it sound reasonable to have it as you may work in multi domain environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The solution for you to add the desired domain to the user-ip-mapping from the User-ID agent that is processing the Pulse Secure logs. In User-ID agent settings that is parsing the Pulse Secure syslog messages go to User Identification -&amp;gt; Discovery -&amp;gt; Servers -&amp;gt; Edit you Pulse Secure entry and add the domain the same way as you see it the group mapping&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1659954445361.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/43039i66425F9CB1B5C38A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1659954445361.png" alt="Astardzhiev_0-1659954445361.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 10:27:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/511208#M106290</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-08-08T10:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Domain Name from LDAP user mapping IMPOSIBLE =(</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/511296#M106302</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Thanks for the answer. This worked as expected for Windows users but&lt;BR /&gt;problems came for MAC users or Iphone Users.&lt;BR /&gt;&lt;BR /&gt;In my company the IOS devices are not part of the active directory domain&lt;BR /&gt;and for instance there is no way where a USERID agent can find domain&lt;BR /&gt;events on the active directory.&lt;BR /&gt;&lt;BR /&gt;For me the solution came to avoid this domain mapping on firewall level, i&lt;BR /&gt;have had a case with the vendor for more than a month and am still waiting&lt;BR /&gt;to find the way....&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 09 Aug 2022 10:46:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/511296#M106302</guid>
      <dc:creator>alvaroarcaz</dc:creator>
      <dc:date>2022-08-09T10:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: Remove Domain Name from LDAP user mapping IMPOSIBLE =(</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/568911#M114779</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;stated above, you can add in whatever domain you want.&amp;nbsp; Below, I'm using a syslog filter to capture the username via syslog, no domain added.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="userid-log.PNG" style="width: 627px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55765i3E24CE6013B845CA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="userid-log.PNG" alt="userid-log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I update the syslog sender config to include a domain (mydomain).&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="syslog-sender-domain.PNG" style="width: 446px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55766iDDF100356D0DF758/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="syslog-sender-domain.PNG" alt="syslog-sender-domain.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I trigger another syslog message, and the domain I specified is added.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="domain-add.PNG" style="width: 677px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/55767iD7EED36DBFF7BA01/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="domain-add.PNG" alt="domain-add.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 16:01:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/remove-domain-name-from-ldap-user-mapping-imposible/m-p/568911#M114779</guid>
      <dc:creator>jbworley</dc:creator>
      <dc:date>2023-12-07T16:01:05Z</dc:date>
    </item>
  </channel>
</rss>

