<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic problem with groups in user-id mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21887#M15985</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i have a problem with using groups (from windows active directory) in security rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on our windows active directory i have created a new group fw_finance. we use the PAN user-id agent to get the mapping from ip to user. i mapped this group on our PA-500 (user identification - group mapping settings). than i created a new security rule, that all users in this group can use port 3048 outgoing. so far so good. but if the users in this group try to connect the port 3048 outside, they will be dropped. on CLI i see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;tettrich@fw003&amp;gt; show user ip-user-mapping ip 10.50.2.97&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IP address:&amp;nbsp; 10.50.2.97&lt;/P&gt;&lt;P&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; assona\cheXXX&lt;/P&gt;&lt;P&gt;Ident. By:&amp;nbsp;&amp;nbsp; AD&lt;/P&gt;&lt;P&gt;Idle Timeout: 2417s&lt;/P&gt;&lt;P&gt;Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 2417s&lt;/P&gt;&lt;P&gt;Groups that the user belongs to (used in policy)&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no group is shown!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;tettrich@fw003&amp;gt; show user group name assona.local\fw_finance&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;group short name: assona.local\fw_finance&lt;/P&gt;&lt;P&gt;[1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\cheiXXX&lt;/P&gt;&lt;P&gt;[2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXX&lt;/P&gt;&lt;P&gt;[3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXXXX&lt;/P&gt;&lt;P&gt;[4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXXX&lt;/P&gt;&lt;P&gt;[5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXXXX&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all users of this group are shown right!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and with &lt;EM&gt;show user user-IDs&lt;/EM&gt; i get also the right information, that user cheiXXX is in the group fw_finance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-500 with software version 4.1.6&lt;/P&gt;&lt;P&gt;User-ID Agent Version 4.1.4-3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can anyone help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Jun 2012 14:50:50 GMT</pubDate>
    <dc:creator>assona</dc:creator>
    <dc:date>2012-06-07T14:50:50Z</dc:date>
    <item>
      <title>problem with groups in user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21887#M15985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i have a problem with using groups (from windows active directory) in security rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on our windows active directory i have created a new group fw_finance. we use the PAN user-id agent to get the mapping from ip to user. i mapped this group on our PA-500 (user identification - group mapping settings). than i created a new security rule, that all users in this group can use port 3048 outgoing. so far so good. but if the users in this group try to connect the port 3048 outside, they will be dropped. on CLI i see the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;tettrich@fw003&amp;gt; show user ip-user-mapping ip 10.50.2.97&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;IP address:&amp;nbsp; 10.50.2.97&lt;/P&gt;&lt;P&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; assona\cheXXX&lt;/P&gt;&lt;P&gt;Ident. By:&amp;nbsp;&amp;nbsp; AD&lt;/P&gt;&lt;P&gt;Idle Timeout: 2417s&lt;/P&gt;&lt;P&gt;Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 2417s&lt;/P&gt;&lt;P&gt;Groups that the user belongs to (used in policy)&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no group is shown!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;tettrich@fw003&amp;gt; show user group name assona.local\fw_finance&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;group short name: assona.local\fw_finance&lt;/P&gt;&lt;P&gt;[1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\cheiXXX&lt;/P&gt;&lt;P&gt;[2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXX&lt;/P&gt;&lt;P&gt;[3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXXXX&lt;/P&gt;&lt;P&gt;[4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXXX&lt;/P&gt;&lt;P&gt;[5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona.local\XXXXXXX&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all users of this group are shown right!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and with &lt;EM&gt;show user user-IDs&lt;/EM&gt; i get also the right information, that user cheiXXX is in the group fw_finance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PA-500 with software version 4.1.6&lt;/P&gt;&lt;P&gt;User-ID Agent Version 4.1.4-3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can anyone help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2012 14:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21887#M15985</guid>
      <dc:creator>assona</dc:creator>
      <dc:date>2012-06-07T14:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: problem with groups in user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21888#M15986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the output provided I would guess the domain is set to 'assona.local' when it should be set to NETBIOS name 'assona'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The output should show as follows:&lt;/P&gt;&lt;PRE style="margin:10px 20px;padding-left:10px;font-size:1.2em;color:#000000"&gt;&lt;CODE&gt;tettrich@fw003&amp;gt; show user ip-user-mapping ip 10.50.2.97

IP address:&amp;nbsp; 10.50.2.97
User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; assona\cheXXX
Ident. By:&amp;nbsp;&amp;nbsp; AD
Idle Timeout: 2417s
Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 2417s
Groups that the user belongs to (used in policy)&lt;/CODE&gt;&lt;/PRE&gt;&lt;PRE style="margin:10px 20px;padding-left:10px;font-size:1.2em;color:#000000"&gt;&lt;SPAN style="font-size: 1.2em;"&gt;tettrich@fw003&amp;gt; show user group name assona\fw_finance&lt;/SPAN&gt;&lt;/PRE&gt;&lt;PRE style="margin:10px 20px;padding-left:10px;font-size:1.2em;color:#000000"&gt;&lt;PRE style="margin: 10px 20px; padding-left: 10px; font-size: 1.2em; color: #000000;"&gt;&lt;CODE&gt;
group short name: assona\fw_finance
[1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona\cheiXXX
[2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona\XXXXX
[3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona\XXXXXXX
[4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona\XXXXXX
[5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ] assona\XXXXXXX&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/PRE&gt;&lt;PRE style="margin:10px 20px;padding-left:10px;font-size:1.2em;color:#000000"&gt;&lt;/PRE&gt;&lt;P&gt;Please let me know if this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jun 2012 17:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21888#M15986</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-06-07T17:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: problem with groups in user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21889#M15987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks! i renamed the domain from &lt;EM&gt;assona.local&lt;/EM&gt; to &lt;EM&gt;assona&lt;/EM&gt; and it works. &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2012 12:42:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21889#M15987</guid>
      <dc:creator>assona</dc:creator>
      <dc:date>2012-06-11T12:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: problem with groups in user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21890#M15988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a PA-500 in a single forest single domain environment and have installed UIA on one of our DCs.&lt;/P&gt;&lt;P&gt;Problem is user-id is not working in Security policies and the PA box does not recognise group membership.&lt;/P&gt;&lt;P&gt;Thing I would like to check with you guys are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Port number for LDAP server profile which is 389&lt;/P&gt;&lt;P&gt;-User-id agent port; we are using 5007. Should we use another port?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also show user group name "domain\domain admins" results in the following message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User group 'domain\domain admins' does not exist or does not have members&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 04:56:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21890#M15988</guid>
      <dc:creator>sthscadmin</dc:creator>
      <dc:date>2012-10-18T04:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: problem with groups in user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21891#M15989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using port 5007 should be fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A common mistake when using port 389 is to forget to uncheck 'SSL'. Since ldap port 389 does not use ssl, please verify that 'SSL' is unchecked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 21:50:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21891#M15989</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-10-18T21:50:53Z</dc:date>
    </item>
    <item>
      <title>Re: problem with groups in user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21892#M15990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSL is unchecked.&lt;/P&gt;&lt;P&gt;It was all working good before we updated from PAN-OS 4.1.6 to 4.1.7 then it stopped working.&lt;/P&gt;&lt;P&gt;Have updated to 4.1.8 but still no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Next I'm going to try is to create new Global Security groups and apply rules to those new groups and see how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have tried with both Universal and Global groups but ....no change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Vaughan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Oct 2012 03:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21892#M15990</guid>
      <dc:creator>sthscadmin</dc:creator>
      <dc:date>2012-10-23T03:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: problem with groups in user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21893#M15991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That just helped me out too! Thanks for the info.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 00:11:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-with-groups-in-user-id-mapping/m-p/21893#M15991</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2013-07-23T00:11:19Z</dc:date>
    </item>
  </channel>
</rss>

