<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Groups not working in Policies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558338#M113246</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;This has nothing to do with user-id and anything related to what we are trying to fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sinkhole IP is used by&amp;nbsp; the DNS Security, which is part of the Anti-Spyware profile. I don't recall to have seen such error, but:&lt;/P&gt;
&lt;P&gt;- Check what spyware profiles you have created. What are you using for sinkhole ip on the DNS security tab?&lt;/P&gt;
&lt;P&gt;- Do you have license for Theat Prevent or DNS Sec? You mentioned this is lab.&lt;/P&gt;
&lt;P&gt;- Try to remove any spyware profiles for now, just to be able to push the config for group mapping.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Sep 2023 11:03:59 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2023-09-18T11:03:59Z</dc:date>
    <item>
      <title>AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558073#M113191</link>
      <description>&lt;P&gt;Hello all, this sounds very similar to a previous post I found on here but I could not see a resolution. Very basic. I am trying to block or allow a domain user from the internet, from LAN zone to WAN zone. This will not work if I have domain\user in the Source User Field. I can see a user when I run: &lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user ip-user-mapping all&lt;/P&gt;
&lt;P&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;BR /&gt;--------------------------------------------- ------------------- ------- -------------------------------- -------------- -------------&lt;BR /&gt;172.60.1.1 vsys1 Unknown unknown 1 4&lt;BR /&gt;172.60.1.4 vsys1 Unknown unknown 3 6&lt;BR /&gt;172.60.1.3 vsys1 AD xsoar\geoff.jones 2334 2334&lt;BR /&gt;Total: 3 users&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_0-1694757547028.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53753iFF7DBE3F80C809E3/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_0-1694757547028.png" alt="GWynn_0-1694757547028.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I change the source to ALL then it of course works, either blocking or allowed. Thoughts??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 06:00:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558073#M113191</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-15T06:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558091#M113192</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Please check the following discussion - &lt;A href="https://live.paloaltonetworks.com/t5/next-generation-firewall/gp-amp-saml-wrong-domain-for-group-mapping/m-p/536886#M1259" target="_blank"&gt;https://live.paloaltonetworks.com/t5/next-generation-firewall/gp-amp-saml-wrong-domain-for-group-mapping/m-p/536886#M1259&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please provide output of the commands I have shared in my last post in the above discussion?&lt;/P&gt;
&lt;P&gt;Also can you share little more background of your setup&lt;BR /&gt;- What are you using for AD? On-Prem AD or Azure AD? Are you using LDAP for group mapping?&lt;/P&gt;
&lt;P&gt;- What are you using for user-id information? Server Monitor, User-ID agent or GlobalProtect client?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 07:42:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558091#M113192</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-15T07:42:36Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558104#M113194</link>
      <description>&lt;P&gt;Hello &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; thanks. I am using Windows 2012R2 in a lab setup. I am using LDAP for group mapping yes.&lt;/P&gt;
&lt;P&gt;I am also using server monitor, and yes in this screenshot it's timed out, it keeps doing that as well but separate issue I think!&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user user-attributes user netbios\user&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user user-attributes user fqdn.local\user&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user user-attributes user xsoar.local\user&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user user-attributes user geoffj@xsoar.local&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Primary: xsoar.local\geoff.jones&lt;BR /&gt;Alt User Names:&lt;BR /&gt;1) geoffj@xsoar.local&lt;BR /&gt;2) xsoar.local\geoffj&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user user-attributes user xsoar.local\geoffj&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user user-attributes user xsoar.local\geoffj&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_0-1694771126032.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53757i206F9792A98D5C11/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_0-1694771126032.png" alt="GWynn_0-1694771126032.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 09:49:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558104#M113194</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-15T09:49:28Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558144#M113204</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;What is the output from&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; debug user-id dump domain-map&lt;/LI-CODE&gt;
&lt;P&gt;If you look closely you can see that ip-to-user mapping is mapping your username in the format of "xsoar\geoff.jones", but most probably your group-mapping is using the format "xsoar.local\geoff.jones" (with one additional .local)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You could confirm this also by comparing the output from ip-to-user mapping and group mapping&lt;/P&gt;
&lt;P&gt;What is the output of the command:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; show user group name "cn=&amp;lt;target-user-group&amp;gt;,cn=users,dc=xsoar,dc=local"&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check also the links for domain-map&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVDCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVDCA0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 15:35:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558144#M113204</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-15T15:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558252#M113230</link>
      <description>&lt;P&gt;Hello, I have done this and reset the mappings as per: but now what? It appears the Palo pulls in the FQDN then converts it to Netbios name, I am still not sure how to resolve this?&lt;/P&gt;
&lt;PRE class="ckeditor_codeblock"&gt;&lt;SPAN&gt; debug user-id reset group-mapping all&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;Restart User-ID by using the command&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE class="ckeditor_codeblock"&gt;&lt;SPAN&gt;&amp;gt; debug software restart process user-id&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;&lt;SPAN&gt;Confirm that the domain map now exits.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE class="ckeditor_codeblock"&gt;&lt;SPAN&gt;&amp;gt; debug user-id dump domain-map&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Sep 2023 22:26:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558252#M113230</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-17T22:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558323#M113238</link>
      <description>&lt;P&gt;admin@GeoffFirewall&amp;gt; debug user-id dump domain-map&lt;/P&gt;
&lt;P&gt;xsoar.local : xsoar&lt;BR /&gt;vsys1 dc=xsoar,dc=local&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:admin@GeoffFirewall&amp;gt;" target="_blank"&gt;admin@GeoffFirewall&amp;gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;______________________________________________________&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user group name "cn=full-access,cn=users,dc=xsoar,dc=local"&lt;/P&gt;
&lt;P&gt;short name: xsoar.local\full-access&lt;/P&gt;
&lt;P&gt;source type: ldap&lt;BR /&gt;source: xsoar.local-GroupMapping&lt;/P&gt;
&lt;P&gt;[1 ] xsoar.local\geoff&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:11:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558323#M113238</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T10:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558324#M113239</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Domain mapping look good now. However probably your group-mapping may need some adjustment.&lt;/P&gt;
&lt;P&gt;Can you share your group mapping config?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558324#M113239</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T10:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558327#M113240</link>
      <description>&lt;P&gt;You mean this??&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_0-1695032882386.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53798iAD381353C420A351/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_0-1695032882386.png" alt="GWynn_0-1695032882386.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558327#M113240</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T10:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558328#M113241</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;That is needed as well, but in addition - have you define anything in the "Domain" field on the "Server profile" tab? It looks you did, but can you confirm?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:30:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558328#M113241</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T10:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558330#M113242</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_0-1695033106931.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53799i42F20A06EF7C3E8E/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_0-1695033106931.png" alt="GWynn_0-1695033106931.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:31:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558330#M113242</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T10:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558331#M113243</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp; for your help BTW!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:32:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558331#M113243</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T10:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558333#M113244</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;I think we are getting closer:&lt;/P&gt;
&lt;P&gt;- Domain field in the group mapping is optional. If you add something there it will &lt;U&gt;override&lt;/U&gt; the domain that collected by the firewall with the LDAP queries.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-users-to-groups#id44a39121-660d-4197-abe7-26c897b64e7e" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/user-id/map-users-to-groups#id44a39121-660d-4197-abe7-26c897b64e7e&lt;/A&gt;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;(Optional) By default, the User Domain field is blank: the firewall automatically detects the domain names for Active Directory (AD) servers. If you enter a value, it overrides any domain names that the firewall retrieves from the LDAP source. For most configurations, if you need to enter a value, enter the NetBIOS domain name (for example, example not example.com). &lt;/LI-CODE&gt;
&lt;P&gt;- In addition on the "user and group attributes" you are using the default settings, which tells the user to collect sAMAccountName and userPrincipalName. This can be confirmed by looking at the user attributes that FW is assciating with user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;dmin@GeoffFirewall&amp;gt; show user user-attributes user geoffj@xsoar.local


Primary: xsoar.local\geoff.jones
Alt User Names:
1) geoffj@xsoar.local
2) xsoar.local\geoffj&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However since you are overriding the domain in the group-mapping that user does no longer matching.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please try to remove the domain from the group mapping and force group-mapping refresh with&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; debug user-id refresh group-mapping all&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558333#M113244</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T10:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558336#M113245</link>
      <description>&lt;P&gt;OK, I have removed the domain but when I commit I now get this!&lt;/P&gt;
&lt;DIV id="x-form-el-ext-comp-5228" class="x-form-element" style="padding-left: 75px; padding-top: 3px;"&gt;
&lt;DIV id="ext-comp-5228" class=" x-form-display-field" style="padding-top: 0px; height: auto;"&gt;
&lt;UL&gt;
&lt;LI&gt;Error: Profile compiler : failed to get PAN sinkhole ip&lt;/LI&gt;
&lt;LI&gt;(Module: device)&lt;/LI&gt;
&lt;LI&gt;client device phase 1 failure&lt;/LI&gt;
&lt;LI&gt;Commit failed&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;A quick Google has not helped!&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 18 Sep 2023 10:51:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558336#M113245</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T10:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558338#M113246</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;This has nothing to do with user-id and anything related to what we are trying to fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sinkhole IP is used by&amp;nbsp; the DNS Security, which is part of the Anti-Spyware profile. I don't recall to have seen such error, but:&lt;/P&gt;
&lt;P&gt;- Check what spyware profiles you have created. What are you using for sinkhole ip on the DNS security tab?&lt;/P&gt;
&lt;P&gt;- Do you have license for Theat Prevent or DNS Sec? You mentioned this is lab.&lt;/P&gt;
&lt;P&gt;- Try to remove any spyware profiles for now, just to be able to push the config for group mapping.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:03:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558338#M113246</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T11:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558339#M113247</link>
      <description>&lt;P&gt;Lol I know! I am not doing any of this, this really is a basic setup. I haven't created any such profiles. I have a 60 day license for everything but not long left. Thanks I'll take a look! !!!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558339#M113247</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T11:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558341#M113248</link>
      <description>&lt;P&gt;I can't delete these...I'll keep looking...&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GWynn_0-1695035196607.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/53800iB9D373004391B0FD/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="GWynn_0-1695035196607.png" alt="GWynn_0-1695035196607.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:06:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558341#M113248</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T11:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558346#M113250</link>
      <description>&lt;P&gt;Hello, I have had to reboot everything so let's check the state! Something didn't like something!&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:26:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558346#M113250</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T11:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558352#M113251</link>
      <description>&lt;P&gt;OK, I'm back in and deleted the Domain, committed fine and have run the below command&lt;/P&gt;
&lt;PRE class="lia-code-sample  language-markup"&gt;&lt;CODE&gt;debug user-id refresh group-mapping all&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:32:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558352#M113251</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T11:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558356#M113252</link>
      <description>&lt;P&gt;Hey &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/277338"&gt;@GWynn&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;The refresh is only need to save you time and not waiting for the group-mapping update (defined in the Server profile in group mapping), Rebooting the firewall should have the exact same effect - triggering new LDAP query&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Check the output from group mapping, user-ip&amp;nbsp; mapping and user atttributes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; show user group name "cn=full-access,cn=users,dc=xsoar,dc=local"

&amp;gt; show user user-attributes user

&amp;gt; show user ip-user-mapping all

&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 18 Sep 2023 11:40:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558356#M113252</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-09-18T11:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups not working in Policies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558361#M113256</link>
      <description>&lt;P&gt;Output:&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user group name "cn=full-access,cn=users,dc=xsoar,dc=local"&lt;/P&gt;
&lt;P&gt;short name: xsoar\full-access&lt;/P&gt;
&lt;P&gt;source type: ldap&lt;BR /&gt;source: xsoar&lt;/P&gt;
&lt;P&gt;[1 ] xsoar\geoff&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user user-attributes user geoffj&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt; show user ip-user-mapping all&lt;/P&gt;
&lt;P&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;BR /&gt;--------------------------------------------- ------------------- ------- -------------------------------- -------------- -------------&lt;BR /&gt;172.60.1.6 vsys1 Unknown unknown 2 5&lt;BR /&gt;Total: 1 users&lt;/P&gt;
&lt;P&gt;admin@GeoffFirewall&amp;gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2023 12:03:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-not-working-in-policies/m-p/558361#M113256</guid>
      <dc:creator>GWynn</dc:creator>
      <dc:date>2023-09-18T12:03:20Z</dc:date>
    </item>
  </channel>
</rss>

