<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD interation and recently created user - problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ad-interation-and-recently-created-user-problem/m-p/27882#M20332</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;You said that the user was not part of any group. As such, have you added that user to the Authentication profile for GP Portal / GW as an individual user there?&lt;/P&gt;&lt;P&gt;You can do the reset command - as that forces the LDAP server to pull all the users/ groups from the AD again (before its hourly update).&lt;/P&gt;&lt;P&gt;If you add a new user to a group or to AD, the firewall groups ought to be reset so as to pull any new users / groups on the AD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 26 Jul 2014 07:40:58 GMT</pubDate>
    <dc:creator>sjamaluddin</dc:creator>
    <dc:date>2014-07-26T07:40:58Z</dc:date>
    <item>
      <title>AD interation and recently created user - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-interation-and-recently-created-user-problem/m-p/27880#M20330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using user ID with agents on DC. Today I got strange problem.&lt;/P&gt;&lt;P&gt;I created new user and I try to logon to GP portal and user GP client. Everytime I got in logs invalid username or password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;debug user-id refresh group-mapping all&amp;nbsp; (non-intrusive command)&lt;/P&gt;&lt;P&gt;This command will only fetch the delta/ difference value from the active directory&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id reset group-mapping all&amp;nbsp; (intrusive command)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but it's for group, this user doesn't belogs to any of mapped group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How to force refresh this user?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2014 11:38:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-interation-and-recently-created-user-problem/m-p/27880#M20330</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-04-01T11:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: AD interation and recently created user - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-interation-and-recently-created-user-problem/m-p/27881#M20331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Simple GP authentication shouldn't be affected by any refresh.&lt;/P&gt;&lt;P&gt;If authentication for existing users are working properly (otherwise I would have requested you to check for LDAP conenctivity),&lt;/P&gt;&lt;P&gt;check what you see in authd logs? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try a tcpdump or pcap of the interesting traffic on Palo Alto firewall?&lt;/P&gt;&lt;P&gt;Did you check on DC for user authentication logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Possibly this will help you narrow down.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Apr 2014 13:40:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-interation-and-recently-created-user-problem/m-p/27881#M20331</guid>
      <dc:creator>prb</dc:creator>
      <dc:date>2014-04-01T13:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: AD interation and recently created user - problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-interation-and-recently-created-user-problem/m-p/27882#M20332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;You said that the user was not part of any group. As such, have you added that user to the Authentication profile for GP Portal / GW as an individual user there?&lt;/P&gt;&lt;P&gt;You can do the reset command - as that forces the LDAP server to pull all the users/ groups from the AD again (before its hourly update).&lt;/P&gt;&lt;P&gt;If you add a new user to a group or to AD, the firewall groups ought to be reset so as to pull any new users / groups on the AD&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jul 2014 07:40:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-interation-and-recently-created-user-problem/m-p/27882#M20332</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2014-07-26T07:40:58Z</dc:date>
    </item>
  </channel>
</rss>

