<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN OS 11.1 USER ID ,POLICY BLOC GROUPS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-1-user-id-policy-bloc-groups/m-p/1235254#M124887</link>
    <description>&lt;P&gt;User-ID agent is working, but security policies are not. This is a common issue, and the problem is likely in your policy configuration, not the User-ID agent itself.&lt;/P&gt;
&lt;P&gt;Primary Fixes to Check:&lt;/P&gt;
&lt;OL start="1"&gt;
&lt;LI&gt;
&lt;P&gt;Policy Order: Your specific "allow group" policy must be placed above any broad "allow all users" policy. The firewall processes policies from top to bottom.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Group Mapping: Even if user-to-IP mapping works, the group membership might not be. Go to Device &amp;gt; User Identification &amp;gt; Group Mapping Settings and confirm the group you're using in your policy is included and syncing correctly.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Source Zone: Ensure the source zone in your policy has "User Identification" enabled.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Commit: Always remember to commit your changes for them to take effect.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It's highly probable the issue is with the policy order, which is the most frequent cause of this behavior.&lt;/P&gt;</description>
    <pubDate>Sun, 03 Aug 2025 17:23:23 GMT</pubDate>
    <dc:creator>Mudhireddy</dc:creator>
    <dc:date>2025-08-03T17:23:23Z</dc:date>
    <item>
      <title>PAN OS 11.1 USER ID ,POLICY BLOC GROUPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-1-user-id-policy-bloc-groups/m-p/1235247#M124886</link>
      <description>&lt;P&gt;Hi Paloalto 11.1, user ID agent configured, it's pulling users with ip.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But using policy to block or allow the internet is not working&lt;/P&gt;
&lt;P&gt;It blocks all users; if all domain users are allowed, the internet will be allowed. If a particular group is selected to enable through policy, it is blocked. I can see users in the user ID section and logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please advise&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Aug 2025 12:32:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-1-user-id-policy-bloc-groups/m-p/1235247#M124886</guid>
      <dc:creator>V.John</dc:creator>
      <dc:date>2025-08-03T12:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: PAN OS 11.1 USER ID ,POLICY BLOC GROUPS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-1-user-id-policy-bloc-groups/m-p/1235254#M124887</link>
      <description>&lt;P&gt;User-ID agent is working, but security policies are not. This is a common issue, and the problem is likely in your policy configuration, not the User-ID agent itself.&lt;/P&gt;
&lt;P&gt;Primary Fixes to Check:&lt;/P&gt;
&lt;OL start="1"&gt;
&lt;LI&gt;
&lt;P&gt;Policy Order: Your specific "allow group" policy must be placed above any broad "allow all users" policy. The firewall processes policies from top to bottom.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Group Mapping: Even if user-to-IP mapping works, the group membership might not be. Go to Device &amp;gt; User Identification &amp;gt; Group Mapping Settings and confirm the group you're using in your policy is included and syncing correctly.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Source Zone: Ensure the source zone in your policy has "User Identification" enabled.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Commit: Always remember to commit your changes for them to take effect.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;It's highly probable the issue is with the policy order, which is the most frequent cause of this behavior.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Aug 2025 17:23:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-11-1-user-id-policy-bloc-groups/m-p/1235254#M124887</guid>
      <dc:creator>Mudhireddy</dc:creator>
      <dc:date>2025-08-03T17:23:23Z</dc:date>
    </item>
  </channel>
</rss>

