<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to convince PAN to know UID mapping for all vsys in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-convince-pan-to-know-uid-mapping-for-all-vsys/m-p/18378#M13408</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly. We don't set redistribution between vsys. For now, I don't know yet exactly how to do it right (one IP call to one IP). 2 loopbacks means 2 IPs and 2 IP calls, what we don't want. I can't reconfigure existing loopback as share interface, because its production and UID will stop working... But I will look in tech guide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Jun 2015 08:53:59 GMT</pubDate>
    <dc:creator>segap</dc:creator>
    <dc:date>2015-06-29T08:53:59Z</dc:date>
    <item>
      <title>How to convince PAN to know UID mapping for all vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-convince-pan-to-know-uid-mapping-for-all-vsys/m-p/18376#M13406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use multi-vsys and XMP API for UID. It works fine for vsys1. We use this sintax for login:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;uid-message&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;version&amp;gt;1.0&amp;lt;/version&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;type&amp;gt;update&amp;lt;/type&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;payload&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;login&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;entry name="user1" ip="10.1.1.1" timeout="20"&amp;gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/entry&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/login&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;lt;/payload&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;/uid-message&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After I paste this sintax in &lt;A href="https://10.12.13.21/php/rest/browse.php/user-id" title="https://10.12.13.21/php/rest/browse.php/user-id"&gt;https://PAN_IP/API/&amp;lt;user-id&amp;gt;&lt;/A&gt; I see in CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show user ip-user-mapping ip 10.1.1.1.&lt;/P&gt;&lt;P&gt;IP address:&amp;nbsp; 10.1.1.1 (vsys1)&lt;BR /&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user1&lt;BR /&gt;From:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XMLAPI&lt;BR /&gt;Idle Timeout: 1196s&lt;BR /&gt;Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 1196s&lt;BR /&gt;Groups that the user belongs to (used in policy)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Question is, how to do, that PAN will recognized this user for all vsys?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already enable User Identification in zone in vsys 2, and configure in Device-&amp;gt;User Identification-&amp;gt;Group Mapping Settings LDAP server. I can also see groups in "Group Include List" tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hint?&lt;/P&gt;&lt;P&gt;Thx, Peter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2015 10:31:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-convince-pan-to-know-uid-mapping-for-all-vsys/m-p/18376#M13406</guid>
      <dc:creator>segap</dc:creator>
      <dc:date>2015-06-24T10:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to convince PAN to know UID mapping for all vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-convince-pan-to-know-uid-mapping-for-all-vsys/m-p/18377#M13407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you do the same for all vsys (1 API call per vsys) or set redistribution between VSYS (through the use of loopbacks)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jun 2015 13:38:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-convince-pan-to-know-uid-mapping-for-all-vsys/m-p/18377#M13407</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-06-24T13:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to convince PAN to know UID mapping for all vsys</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-to-convince-pan-to-know-uid-mapping-for-all-vsys/m-p/18378#M13408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Exactly. We don't set redistribution between vsys. For now, I don't know yet exactly how to do it right (one IP call to one IP). 2 loopbacks means 2 IPs and 2 IP calls, what we don't want. I can't reconfigure existing loopback as share interface, because its production and UID will stop working... But I will look in tech guide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jun 2015 08:53:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-to-convince-pan-to-know-uid-mapping-for-all-vsys/m-p/18378#M13408</guid>
      <dc:creator>segap</dc:creator>
      <dc:date>2015-06-29T08:53:59Z</dc:date>
    </item>
  </channel>
</rss>

