<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Group Include List Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32059#M23495</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't count your chickens yet...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've now got a problem with User ID's being detected as domain\user, but all the imported user data is in the form user@domain, which may (or may not) be connected to this fix!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Feb 2012 20:31:31 GMT</pubDate>
    <dc:creator>apackard</dc:creator>
    <dc:date>2012-02-03T20:31:31Z</dc:date>
    <item>
      <title>User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32052#M23488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;On PanOS 4.1.2 I am trying to perform an LDAP lookup for the 'Group Include List' element of the User Identification setup i.e. to populate the 'User' field in policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I do this I get an "bind-dn is invalid" error.&amp;nbsp; I know the account configured is fine, as it is a shared object set in Panorama and pushed to multiple boxes, and it works fine on other boxes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if this error message ia a "red-herring" and just saying that 'something' is wrong - maybe connectivity etc - of does it only appear if it is an authentication error?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ta&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 18:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32052#M23488</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-01-23T18:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32053#M23489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One place to start is to perform a "show user ldap-server state" and double check to see if you have the full Bind DN, and not just partially listed thinking that the base is going to help cover it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know this is not a true answer, but it is a place to start.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 21:53:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32053#M23489</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-24T21:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32054#M23490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that.&amp;nbsp; Got me one stage further, but more confused now!&lt;/P&gt;&lt;P&gt;Used the command "show user group-mapping state all" and it actually showed that the LDAP query is working, and its pulling back *all* the groups from my AD.&lt;/P&gt;&lt;P&gt;However, when I try to 'connect' via the UI it still fails.&amp;nbsp; As this step is required so I can filter my groups to sync against (I don;t want all 4000 in the drop down!) it is quite important, and I can't see why it is connecting in the background, but giving me an auth error when prompting it via the UI.&lt;/P&gt;&lt;P&gt;Any clues gratefully received!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 22:20:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32054#M23490</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-01-24T22:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32055#M23491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Of course you are getting that error because of the way that the Bind DN is listed. Yes, it might work in some instances, but still give that error on that screen. When I look through other cases, this was resolved by modifying the way that the bind-dn is listed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to be able to help you here, but you might need to open a case and work the issue that way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jan 2012 17:07:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32055#M23491</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-26T17:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32056#M23492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have the same issue coming up.&amp;nbsp; Can you guys please let me know on what type of modifications were done to get it running because i tried doing everything i can and have nothing to do now.&amp;nbsp; I did log this case with PAN and even they seem to be lost on it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 16:59:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32056#M23492</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-03T16:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32057#M23493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I changed the format of the account used to query the LDAP servers from user@domain to domain\user and that seemed to fix the UI issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 17:07:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32057#M23493</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-02-03T17:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32058#M23494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;APACKARD... you genius... Thank you very much mate...!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 17:26:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32058#M23494</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-03T17:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32059#M23495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't count your chickens yet...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've now got a problem with User ID's being detected as domain\user, but all the imported user data is in the form user@domain, which may (or may not) be connected to this fix!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 20:31:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32059#M23495</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-02-03T20:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32060#M23496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And just to be clear - they're not matching i.e. if I add a group to&amp;nbsp; a policy that contains my name in the user@domain format, I'm not being matched against traffic with domain\user as a field.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2012 20:33:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32060#M23496</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-02-03T20:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32061#M23497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for sharing the info mate.&amp;nbsp; So far I haven't heard back from the customer yet.&amp;nbsp; Will keep you updated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 09:17:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32061#M23497</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-06T09:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32062#M23498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So far things are looking good with domain\user mate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 11:02:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32062#M23498</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-06T11:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Include List Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32063#M23499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found that I'd incorrectly added the FQDN domain name in the Domain field, rather than the Windows domain name, in the User-ID settings which stopped my users mapping correctly, so all good for me too!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2012 11:05:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-include-list-error/m-p/32063#M23499</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-02-06T11:05:30Z</dc:date>
    </item>
  </channel>
</rss>

