<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Directory help in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28813#M21038</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, you need need to setup a user ID agent to collect user &amp;gt; IP mappings. This can be done with the internal user ID Agent built in to the device or by using the external Windows User ID Agent. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Aug 2013 16:18:57 GMT</pubDate>
    <dc:creator>jteetsel</dc:creator>
    <dc:date>2013-08-14T16:18:57Z</dc:date>
    <item>
      <title>Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28812#M21037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We received our first pan 3020 Monday and I have been trying to learn about the product in order to setup for production. I'm making good progress so far, but I have run into an issue importing AD users. I setup group mapping and I'm able to see groups that were imported, but no users. What am I missing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:03:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28812#M21037</guid>
      <dc:creator>jbo</dc:creator>
      <dc:date>2013-08-14T16:03:32Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28813#M21038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, you need need to setup a user ID agent to collect user &amp;gt; IP mappings. This can be done with the internal user ID Agent built in to the device or by using the external Windows User ID Agent. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:18:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28813#M21038</guid>
      <dc:creator>jteetsel</dc:creator>
      <dc:date>2013-08-14T16:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28814#M21039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you configured ip user mapping as well. Please configure IP user mapping on the firewall, with either the agent or the agentless feature&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can view the users using the below commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;show user group list&lt;/P&gt;&lt;P&gt;This shows the groups that are learnt from the AD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;show user group name &amp;lt;group-name&amp;gt;&lt;/P&gt;&lt;P&gt;This command shows the users associated to that group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Karthik &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:19:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28814#M21039</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-08-14T16:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28815#M21040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you use agentless system ? you configured user identification tab/user mapping&amp;nbsp; and enabled user identification on the zone you need ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:21:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28815#M21040</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-08-14T16:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28816#M21041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Currently I'm agentless. I setup the User Mapping and added server monitors for my dc's. I have Group Mapping Settings setup. LDAP is also setup, but when I click on a policy it only shows groups and no users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 03:08:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28816#M21041</guid>
      <dc:creator>jbo</dc:creator>
      <dc:date>2013-08-15T03:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28817#M21042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you verify if the user mapping shows up the user, use following command to check the same&lt;/P&gt;&lt;P&gt;&amp;gt; show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;If the user is present can you try manually type in the username i.e first couple of letters&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 03:18:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28817#M21042</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2013-08-15T03:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28818#M21043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I just stumbled into my issue. Under "Server Profiles", "LDAP" I had domain.local in the domain field. So it was listing all of my users as domain.local\username. So when I was trying to find the users they didn't show up as domain\username. Amazing such a problem from one little field. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all the help guys.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 03:19:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28818#M21043</guid>
      <dc:creator>jbo</dc:creator>
      <dc:date>2013-08-15T03:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28819#M21044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's because you provide domain.local - change it to domain&lt;/P&gt;&lt;P&gt;please read this topic &lt;A __default_attr="5050" __jive_macro_name="thread" class="jive_macro jive_macro_thread" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 09:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28819#M21044</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-08-15T09:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: Active Directory help</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28820#M21045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jbo, &lt;/P&gt;&lt;P&gt;In the ldap profile under domain it is suppose to be netbios domain name and not FQDN. If you specify a wrong netbios domain name then the mapping will be incorrect and policies will not work correctly either. The reason is it appends the netbios domain name&amp;nbsp; you specify when it mapping the users. Hope that helps.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Numan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Aug 2013 15:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-directory-help/m-p/28820#M21045</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2013-08-15T15:21:48Z</dc:date>
    </item>
  </channel>
</rss>

