<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall suddenly stopped reading EntraID groups from CIE in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-suddenly-stopped-reading-entraid-groups-from-cie/m-p/1229129#M124298</link>
    <description>&lt;P&gt;Thank you for the reply, all 4 of our firewalls are listed under device association on common services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;output from those commands are:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StianKantebakke_0-1747291559228.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67611i1B895450D95066B6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="StianKantebakke_0-1747291559228.png" alt="StianKantebakke_0-1747291559228.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 May 2025 06:46:30 GMT</pubDate>
    <dc:creator>StianKantebakke</dc:creator>
    <dc:date>2025-05-15T06:46:30Z</dc:date>
    <item>
      <title>Firewall suddenly stopped reading EntraID groups from CIE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-suddenly-stopped-reading-entraid-groups-from-cie/m-p/1229053#M124291</link>
      <description>&lt;P&gt;We have been using CIE for about half a year now for a spesific usecase where we use som groups that are maintained in Entra ID to control network access, monday we were made aware that that access did not update for new users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CIE does have the correct group mapping, but the firewalls does not sync with CIE.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Debugging the issue we have found that the firewall does not manage to find the instance of CIE:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StianKantebakke_0-1747212225376.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67599iA028FC356C72FD63/image-size/medium?v=v2&amp;amp;px=400" role="button" title="StianKantebakke_0-1747212225376.png" alt="StianKantebakke_0-1747212225376.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;We checked with a second pair of firewalls we have on the same tennant and the same issure happens there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the logs we have found one supicious event about instance region 'kr' that started monday(have repeated multiple times), but dont find anything in the config that refers to that region:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StianKantebakke_1-1747212443937.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67600i448CF2611BC1F07F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="StianKantebakke_1-1747212443937.png" alt="StianKantebakke_1-1747212443937.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;looking at the log in the cli we found some more errors:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StianKantebakke_2-1747212811193.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67601iE69FA83F7EDB1E04/image-size/medium?v=v2&amp;amp;px=400" role="button" title="StianKantebakke_2-1747212811193.png" alt="StianKantebakke_2-1747212811193.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In the traffic log all traffic out from the management ip is allowed. The firewalls device certificate is valid.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have repportet the problem to partner support, have not had the need to use them before so dont know what to expect, but they have broken the 4h responce time at least now &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So reaching out here to hear if someone got some suggestions of possible errors or have experienced something similar before?&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 09:09:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-suddenly-stopped-reading-entraid-groups-from-cie/m-p/1229053#M124291</guid>
      <dc:creator>StianKantebakke</dc:creator>
      <dc:date>2025-05-14T09:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall suddenly stopped reading EntraID groups from CIE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-suddenly-stopped-reading-entraid-groups-from-cie/m-p/1229056#M124292</link>
      <description>&lt;P&gt;make sure the firewall is properly associated to your tenant via common services &amp;gt; device association&lt;/P&gt;
&lt;P&gt;verify that the device certificate is valid and not throwing an error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;whats the output of&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;show device-certificate status

show user cloud-identity-engine status all&lt;/LI-CODE&gt;
&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 May 2025 11:03:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-suddenly-stopped-reading-entraid-groups-from-cie/m-p/1229056#M124292</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2025-05-14T11:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall suddenly stopped reading EntraID groups from CIE</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/firewall-suddenly-stopped-reading-entraid-groups-from-cie/m-p/1229129#M124298</link>
      <description>&lt;P&gt;Thank you for the reply, all 4 of our firewalls are listed under device association on common services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;output from those commands are:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="StianKantebakke_0-1747291559228.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67611i1B895450D95066B6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="StianKantebakke_0-1747291559228.png" alt="StianKantebakke_0-1747291559228.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 May 2025 06:46:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/firewall-suddenly-stopped-reading-entraid-groups-from-cie/m-p/1229129#M124298</guid>
      <dc:creator>StianKantebakke</dc:creator>
      <dc:date>2025-05-15T06:46:30Z</dc:date>
    </item>
  </channel>
</rss>

