<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to assign Security Policy to Users or Groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35731#M26251</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1109" data-externalid="" data-presence="null" data-userid="5002" data-username="rkalugdan" href="https://live.paloaltonetworks.com/people/rkalugdan" id="jive-500210066828985651834"&gt;rkalugdan&lt;/A&gt; - &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;No, using the user-id agent as an ldap proxy does not work to pull groups.&amp;nbsp; It's interesting because on the Group Mapping tab (Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; Group Include List), I can see all my ldap groups, browse them, etc.. however, I cannot use any of those groups to assign policy to.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 May 2013 18:51:17 GMT</pubDate>
    <dc:creator>MRosloniec</dc:creator>
    <dc:date>2013-05-23T18:51:17Z</dc:date>
    <item>
      <title>Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35720#M26240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi -&lt;/P&gt;&lt;P&gt;We are using User-ID Agents to create user-to-IP mappings and I've got group mapping configured on the firewall itself and I can browse through my ldap groups.&amp;nbsp; However, when I go to Policies &amp;gt; Security Policy I am unable to select either individual users OR groups to assign the policy to... Nothing populates.&amp;nbsp; Am I missing something somewhere?&amp;nbsp; Seems like it would be straight forward after configuring group mapping.&amp;nbsp; Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 17:33:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35720#M26240</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T17:33:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35721#M26241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what's the output for the following?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@PA-200&amp;gt; show user group-mapping state all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 17:50:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35721#M26241</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2013-05-23T17:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35722#M26242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what panos version are you using ?&lt;/P&gt;&lt;P&gt;if you configured user id,ldap and group mapping.and also enabled user-id on a zone&lt;/P&gt;&lt;P&gt;you should see users on monitor tab traffic logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if everythins is ok and you can't see user/group on security rule&lt;/P&gt;&lt;P&gt;reboot the device if you can, you'll see groups and users on security rule after that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:03:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35722#M26242</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-23T18:03:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35723#M26243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="mailto:admin@UTM21-LAB-2-B(active"&gt;admin@UTM21-LAB-2-B(active&lt;/A&gt;)&amp;gt; show user group-mapping state all&lt;/P&gt;&lt;P&gt;&amp;lt;response status="success"&amp;gt;&amp;lt;result&amp;gt;&lt;BR /&gt;Group Mapping(vsys1, type: active-directory): Group_Mapping (job 749073)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bind DN&amp;nbsp;&amp;nbsp;&amp;nbsp; : cn=ldap-alt-paloalto,ou=users,o=alticor&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ou=groups,o=alticor&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Filter: (&amp;amp;(objectCategory=Group)(objectClass=group))&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Filter: (&amp;amp;(objectCategory=person)(objectClass=user))&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Servers&amp;nbsp;&amp;nbsp;&amp;nbsp; : configured 1 servers&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap-adam-apps.intranet.local(389)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Proxy state: QUERY_SENT&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Query agent: usnx282&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Result from: usnx282&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: 326 secs ago(took 6 secs)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Action Time: Now (started 156 secs ago)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Query Local Group Mapping Service:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: 326 secs ago(took 6 secs)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Action Time: Now (started 156 secs ago)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Groups: 0&lt;BR /&gt;&amp;lt;/result&amp;gt;&amp;lt;/response&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:03:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35723#M26243</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T18:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35724#M26244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see any groups being pulled. If you're not filtering groups, we should be able to pull all groups in your AD as shown below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group Mapping(vsys1, type: active-directory): amb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bind DN&amp;nbsp;&amp;nbsp;&amp;nbsp; : renato@amb.local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : DC=amb,DC=local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Filter: (None)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Filter: (None)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Servers&amp;nbsp;&amp;nbsp;&amp;nbsp; : configured 1 servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.16.20.23(389)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: 1 secs ago(took 0 secs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Action Time: In 3599 secs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Groups: 42&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=administrators,cn=builtin,dc=amb,dc=local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=domain controllers,cn=users,dc=amb,dc=local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=remote desktop users,cn=builtin,dc=amb,dc=local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=distributed com users,cn=builtin,dc=amb,dc=local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=incoming forest trust builders,cn=builtin,dc=amb,dc=local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cn=certificate service dcom access,cn=builtin,dc=amb,dc=local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does the ldap server profile look like? Grep after the output is displayed on your ssh terminal with the following: "/ldap" and "/group-mapping"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@PA-200&amp;gt; show config running&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; amb {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; amb {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 389;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; address 172.16.20.23;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap-type active-directory;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; base DC=amb,DC=local;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bind-dn renato@amb.local;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timelimit 30;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bind-timelimit 30;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bind-password -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl no;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain amb;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; group-mapping {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; amb {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; group-object group;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; group-name name;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; group-member member;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user-object person;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; user-name sAMAccountName;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled no;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server-profile amb;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:15:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35724#M26244</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2013-05-23T18:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35725#M26245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As pointed out in the previous comment, there are no groups being pulled.&lt;/P&gt;&lt;P&gt;Looks like you are using the userID agent for "LDAP Proxy" to query for groups. Does the management interface of the firewall have connectivity to the domain controllers? If so, can you please try to uncheck the "LDAP proxy" checkbox on the userID agent (Device&amp;gt;User identification&amp;gt;User ID agents) and see if groups get pulled?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:25:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35725#M26245</guid>
      <dc:creator>goku123</dc:creator>
      <dc:date>2013-05-23T18:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35726#M26246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you see groups on group mapping tab or not ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35726#M26246</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-23T18:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35727#M26247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="replyToName"&gt;rkalugdan I have to apologize - I'm not familiar with running the grep command from the CLI.&amp;nbsp; Can you provide the syntax?&amp;nbsp; I'm on 5.0.4&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:36:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35727#M26247</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T18:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35728#M26248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I can see groups on the group mapping tab.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:37:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35728#M26248</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T18:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35729#M26249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I initially had the Use LDAP Proxy box unchecked.&amp;nbsp; I checked it as a way to try to resolve this issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:38:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35729#M26249</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T18:38:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35730#M26250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so you're now using the user-id agent as an ldap proxy to pull groups. possibly will need to review your ldap server profile to get a better understanding of the issue. glad you were able to get a work around implemented.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:47:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35730#M26250</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2013-05-23T18:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35731#M26251</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1109" data-externalid="" data-presence="null" data-userid="5002" data-username="rkalugdan" href="https://live.paloaltonetworks.com/people/rkalugdan" id="jive-500210066828985651834"&gt;rkalugdan&lt;/A&gt; - &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;No, using the user-id agent as an ldap proxy does not work to pull groups.&amp;nbsp; It's interesting because on the Group Mapping tab (Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; Group Include List), I can see all my ldap groups, browse them, etc.. however, I cannot use any of those groups to assign policy to.&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:51:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35731#M26251</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T18:51:17Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35732#M26252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;show us the ldap config&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:52:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35732#M26252</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2013-05-23T18:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35733#M26253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you try to reboot your device ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 18:53:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35733#M26253</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-23T18:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35734#M26254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What CLI command will provide the output you're looking for, &lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1109" data-externalid="" data-presence="null" data-userid="5002" data-username="rkalugdan" href="https://live.paloaltonetworks.com/people/rkalugdan" id="jive-500210067517795324391"&gt;rkalugdan&lt;/A&gt;?&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 19:01:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35734#M26254</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T19:01:32Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35735#M26255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show shared server-profile ldap&lt;/P&gt;&lt;P&gt;in configure mode.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 19:13:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35735#M26255</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-05-23T19:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35736#M26256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="mailto:admin@Ada-PAN-M100(primary-active"&gt;admin@Ada-PAN-M100(primary-active&lt;/A&gt;)# show template "US Lab" config shared server-profile ldap LDAP-Group-Mapping&lt;/P&gt;&lt;P&gt;LDAP-Group-Mapping {&lt;/P&gt;&lt;P&gt;&amp;nbsp; server {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap-adam-apps.intranet.local {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 389;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; address ldap-adam-apps.intranet.local;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; ldap-type active-directory;&lt;/P&gt;&lt;P&gt;&amp;nbsp; timelimit 30;&lt;/P&gt;&lt;P&gt;&amp;nbsp; bind-timelimit 30;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl no;&lt;/P&gt;&lt;P&gt;&amp;nbsp; domain na;&lt;/P&gt;&lt;P&gt;&amp;nbsp; base ou=groups,o=alticor;&lt;/P&gt;&lt;P&gt;&amp;nbsp; bind-dn cn=ldap-alt-paloalto,ou=users,o=alticor;&lt;/P&gt;&lt;P&gt;&amp;nbsp; bind-password -AQ==ZtJUGAV/ZcKHS4UkVNe1zXA0x2s=uvilr+9UMZiJgEAXcnLCXA==;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 May 2013 19:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35736#M26256</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-05-23T19:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35737#M26257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The M-100 (and Panorama in general) will not populate users or groups when creating rules until a rule has been created with that user/group at least once. The reason for this is because of the huge amount of load it would take if you had several hundred firewalls, each with different domains configured with a single Panorama (imagine how long it would take to query each firewall, which would query each domain, and return the full group and user list).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you create the policy local to the firewall, the group will indeed prepopulate because the scope is limited to that one firewall's set of user and group data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you create a policy which has a user- or group-name on Panorama, that user/group will be available for future rules. Note that there is no integrity check, so a mistake will be allowed through and simply fail to match. I recommend copying the user data from an LDAP browser so you don't have to worry about the syntax.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Greg Wesson &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 00:12:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35737#M26257</guid>
      <dc:creator>gwesson</dc:creator>
      <dc:date>2013-05-24T00:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35738#M26258</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This sound like a bug...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was the master device selected in the Device Group configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User-ID groups should be pulled from the Master Device for selection in Policy and will also be queried upon search to pull individual users as well.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Screen Shot 2013-05-23 at 5.19.13 PM.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6652_Screen Shot 2013-05-23 at 5.19.13 PM.png" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 00:21:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35738#M26258</guid>
      <dc:creator>mschuricht</dc:creator>
      <dc:date>2013-05-24T00:21:56Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to assign Security Policy to Users or Groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35739#M26259</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes there is a master device set.&amp;nbsp; We went ahead and opened a case on this issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2013 17:47:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-assign-security-policy-to-users-or-groups/m-p/35739#M26259</guid>
      <dc:creator>MRosloniec</dc:creator>
      <dc:date>2013-06-04T17:47:38Z</dc:date>
    </item>
  </channel>
</rss>

