<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 4.1.7 LDAP lookup unstable in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-ldap-lookup-unstable/m-p/34531#M25334</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I opened a case which got escalated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue #1)&amp;nbsp; Under Group Mapping Settings, I had a seperate mapping for each active directory group I wanted to use on my PA 2050.&amp;nbsp; I have a single forest/AD.&amp;nbsp;&amp;nbsp; Support recommended having a single group mapping setting which included all of my active directory groups that I wanted to use within my Palo Alto rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue #2) Under Server Profiles / LDAP we modified the settings to use port 389 instead of the GC port &lt;SPAN style="text-align: left; background-color: #ffffff; text-indent: 0px; color: #222222;"&gt;3268.&amp;nbsp;&amp;nbsp; We modified the Bind DN from &lt;A href="mailto:user@domain.com"&gt;user@domain.com&lt;/A&gt; to CN=user,OU=grouping,OU=container,DC=domain,DC=com&amp;nbsp;&amp;nbsp; (That's not my actual user or domain.)&amp;nbsp;&amp;nbsp; Support states this works better.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-align: left; background-color: #ffffff; text-indent: 0px; color: #222222;"&gt;Issue #3)&amp;nbsp; The command &lt;STRONG&gt;show user user-IDs | match joe&amp;nbsp; &lt;/STRONG&gt;is not showing all of joe's group membership as this is filtering out lines with joe.&amp;nbsp; The group membership list includes lines that do not have joe in the line.&amp;nbsp; So I was using the command incorrectly.&amp;nbsp; The proper command is &lt;STRONG&gt;show user user-IDs match-user joe&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-align: left; background-color: #ffffff; text-indent: 0px; color: #222222;"&gt;Considering I didn't have the LDAP instability for a few weeks, and then it poped up it's ugly head, only time will tell for certain if these are the fixes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 06 Sep 2012 21:51:26 GMT</pubDate>
    <dc:creator>EdwinD</dc:creator>
    <dc:date>2012-09-06T21:51:26Z</dc:date>
    <item>
      <title>4.1.7 LDAP lookup unstable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-ldap-lookup-unstable/m-p/34530#M25333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have three active directory servers configured within the LDAP settings of my Palo Alto.&amp;nbsp; I have tried using both 389 and the GC port of 3268 as per this doc: &lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3120"&gt;https://live.paloaltonetworks.com/docs/DOC-3120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two 2050's in an active/passive pair.&amp;nbsp; I have AD IP agents on each DC and the PAs are set to query them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that while I can see the users in my traffic logs, they are getting the wrong security policies applied to them.&amp;nbsp; The user to IP is working, it is the user to LDAP group which is not.&amp;nbsp;&amp;nbsp; I am &lt;STRONG&gt;not&lt;/STRONG&gt; using the user agents as LDAP group membership proxies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I do &lt;STRONG&gt;show user user-IDs | match joe&amp;nbsp; &lt;/STRONG&gt;I may get back the proper group, but I may only get back one of three groups the user is a member of.&amp;nbsp;&amp;nbsp; I'm talking about 1 of 3 groups I've defined to the Palo Alto, not all Active Directory groups.&amp;nbsp;&amp;nbsp; The results are very random.&amp;nbsp;&amp;nbsp; If I run the same command on the second PA in the pair, I will often see different results.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ran the command&amp;nbsp; &lt;STRONG&gt;show user group-mapping state all&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;and while I did have some nested groups, I do not anymore.&amp;nbsp; Because I cannot negate user groups in a security policy, I have user groups which contain 1500+ users.&amp;nbsp;&amp;nbsp; I have the maximum timeout value set to 30 seconds, which is the max I can set it to in 4.1.7.&amp;nbsp;&amp;nbsp; Per the state all command, it is taking no more than 5 seconds to enumerate these groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone please shed some light on what's going on, and how to fix this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 23:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-ldap-lookup-unstable/m-p/34530#M25333</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2012-09-05T23:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: 4.1.7 LDAP lookup unstable</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-ldap-lookup-unstable/m-p/34531#M25334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I opened a case which got escalated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue #1)&amp;nbsp; Under Group Mapping Settings, I had a seperate mapping for each active directory group I wanted to use on my PA 2050.&amp;nbsp; I have a single forest/AD.&amp;nbsp;&amp;nbsp; Support recommended having a single group mapping setting which included all of my active directory groups that I wanted to use within my Palo Alto rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Issue #2) Under Server Profiles / LDAP we modified the settings to use port 389 instead of the GC port &lt;SPAN style="text-align: left; background-color: #ffffff; text-indent: 0px; color: #222222;"&gt;3268.&amp;nbsp;&amp;nbsp; We modified the Bind DN from &lt;A href="mailto:user@domain.com"&gt;user@domain.com&lt;/A&gt; to CN=user,OU=grouping,OU=container,DC=domain,DC=com&amp;nbsp;&amp;nbsp; (That's not my actual user or domain.)&amp;nbsp;&amp;nbsp; Support states this works better.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-align: left; background-color: #ffffff; text-indent: 0px; color: #222222;"&gt;Issue #3)&amp;nbsp; The command &lt;STRONG&gt;show user user-IDs | match joe&amp;nbsp; &lt;/STRONG&gt;is not showing all of joe's group membership as this is filtering out lines with joe.&amp;nbsp; The group membership list includes lines that do not have joe in the line.&amp;nbsp; So I was using the command incorrectly.&amp;nbsp; The proper command is &lt;STRONG&gt;show user user-IDs match-user joe&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-align: left; background-color: #ffffff; text-indent: 0px; color: #222222;"&gt;Considering I didn't have the LDAP instability for a few weeks, and then it poped up it's ugly head, only time will tell for certain if these are the fixes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Sep 2012 21:51:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-ldap-lookup-unstable/m-p/34531#M25334</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2012-09-06T21:51:26Z</dc:date>
    </item>
  </channel>
</rss>

