<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UserID/Group mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557592#M113121</link>
    <description>&lt;P&gt;We are running 10.2.3 both on Panorama and fw. So thats probably whats wrong. Only thing is that I cant add the config manually on the local fw. Says i need to override the template. And there isnt any gear icon to override... What vers. Panos is this fixed in?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/M&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Sep 2023 18:31:13 GMT</pubDate>
    <dc:creator>149999mah3</dc:creator>
    <dc:date>2023-09-12T18:31:13Z</dc:date>
    <item>
      <title>UserID/Group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557523#M113108</link>
      <description>&lt;P&gt;I have created a LDAP profile, group mapping and user mapping from Panorama, and it seems to be working.&lt;/P&gt;
&lt;P&gt;Im able to do "test authentication username xxxxxxx.test@xxxxxxxxx.com authentication-profile xxxxxx-LDAP password and this works fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My problem is that panorama doesnt seem to be able to "manage" Palo Alto Networks User ID Agent Setup tab.&lt;/P&gt;
&lt;P&gt;That tab is empty on local fw (device-&amp;gt;User identification-&amp;gt;User Mapping), if i enter anything in this tab, anything at all, i get the error msg bellow. Eventho Panorama has this config. I thought it was a template issue, so i created a test template and added all this config&lt;/P&gt;
&lt;P&gt;in the new test template. And put it on top, but no luck. If i try to configure it manually i get the following error msg.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Error: Domain's DNS name is missing in Active Directory Authentication&lt;/LI&gt;
&lt;LI&gt;client useridd phase 1 failure&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From mp-log userid.log:&lt;/P&gt;
&lt;P&gt;2023-09-12 09:18:26.617 +0200 connects to redis_dscd db1&lt;BR /&gt;2023-09-12 09:18:26.716 +0200 dsc adaptor completed rpc call for func ShowUser&lt;BR /&gt;2023-09-12 09:18:26.717 +0200 connects to redis_dscd db1&lt;BR /&gt;2023-09-12 09:19:12.608 +0200 device cert: NEW: cfg.device-cert-status, event change, invalid field!&lt;BR /&gt;2023-09-12 09:19:12.608 +0200 device cert: OLD: cfg.device-cert-status, event change, invalid field!&lt;BR /&gt;2023-09-12 09:19:12.608 +0200 device cert: Recevied (change) event for device cert. Update dsc connections.&lt;BR /&gt;2023-09-12 09:19:12.609 +0200 Error: pan_dsc_rpc_get_thermite_cert(pan_dsc_adaptor.c:691): [THERMITE] dsc rpc get device cert failed&lt;BR /&gt;2023-09-12 09:19:12.609 +0200 dsc adaptor completed rpc call for func UpdateThermiteCert&lt;BR /&gt;2023-09-12 09:20:04.302 +0200 phase1 started&lt;BR /&gt;2023-09-12 09:20:04.304 +0200 parsing config: config length 186610&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 &amp;lt;vsys&amp;gt; tag does not exist&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 mgmt internal: client certificate profile commit&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 No child nodes present under secure connection server mgmt settings, No updates needed.&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 [secure_conn] extract secure_conn userid channel settings SERVER&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 [secure_conn] user_id secure comm enabled for SERVER&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 No child nodes present under secure connection client mgmt settings, No updates needed.&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 [secure_conn] extract secure_conn userid channel settings CLIENT&lt;BR /&gt;2023-09-12 09:20:04.319 +0200 [secure_conn] user_id secure comm enabled for CLIENT&lt;BR /&gt;2023-09-12 09:20:04.322 +0200 [secure_conn] user_id secure conn cfg SERVER:disabled CLIENT:disabled&lt;BR /&gt;2023-09-12 09:20:04.324 +0200 hipreport to icd channel: 1&lt;BR /&gt;2023-09-12 09:20:04.326 +0200 no wmi account is configured, no need to probe&lt;BR /&gt;2023-09-12 09:20:04.327 +0200 Error: pan_user_id_dir_server_parse_cfg(pan_user_id_collector.c:409): Domain's DNS name is missing in Active Directory Authentication&lt;BR /&gt;2023-09-12 09:20:04.327 +0200 Error: pan_user_id_collector_parse_cfg(pan_user_id_collector.c:2217): pan_user_id_dir_server_parse_cfg() failed&lt;BR /&gt;2023-09-12 09:20:04.327 +0200 Error: pan_user_id_parse_vsys_config(pan_user_id_cfg.c:818): pan_userid_collector_parse_cfg() failed&lt;BR /&gt;2023-09-12 09:20:04.327 +0200 Error: pan_user_id_parse_config_i(pan_user_id_cfg.c:1515): pan_user_id_parse_vsys_config() failed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So im missing domains dns name in active directory authentication. If this is the auth profile, i got the user domain set correct. Does anyone know&lt;/P&gt;
&lt;P&gt;where "Domain's DNS name is missing in Active Directory Authentication" is?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/M&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 09:07:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557523#M113108</guid>
      <dc:creator>149999mah3</dc:creator>
      <dc:date>2023-09-12T09:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: UserID/Group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557547#M113111</link>
      <description>&lt;P&gt;What Panorama version are you using?&lt;/P&gt;
&lt;P&gt;It was a bug in Panorama 10.2.x (at least up to 10.2.3) when UserID info in Panorama template was not pushed down to template stack and as a result not sent to firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 12:48:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557547#M113111</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2023-09-12T12:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: UserID/Group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557552#M113112</link>
      <description>&lt;P&gt;Are you using the built in user-id agent for this? If you go to&amp;nbsp;&lt;SPAN&gt;device-&amp;gt;User identification-&amp;gt;User Mapping then click the gear for Palo Alto Networks user-id agent setup, under the "server monitor account" there you'll fill out your account used for authentication as well as the "Domains DNS Name". &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are not using the built in user-id agent, you can just go to the "server monitor" and "client probing" tabs and make sure everything is unchecked there.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 12:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557552#M113112</guid>
      <dc:creator>Claw4609</dc:creator>
      <dc:date>2023-09-12T12:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: UserID/Group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557592#M113121</link>
      <description>&lt;P&gt;We are running 10.2.3 both on Panorama and fw. So thats probably whats wrong. Only thing is that I cant add the config manually on the local fw. Says i need to override the template. And there isnt any gear icon to override... What vers. Panos is this fixed in?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/M&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 18:31:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557592#M113121</guid>
      <dc:creator>149999mah3</dc:creator>
      <dc:date>2023-09-12T18:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: UserID/Group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557593#M113122</link>
      <description>&lt;P&gt;Im using built in, but perhaps ill try the agent now that I know of the bug mentioned above.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 18:34:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/userid-group-mapping/m-p/557593#M113122</guid>
      <dc:creator>149999mah3</dc:creator>
      <dc:date>2023-09-12T18:34:07Z</dc:date>
    </item>
  </channel>
</rss>

