<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 6.0.4 group mapping issue? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/6-0-4-group-mapping-issue/m-p/37005#M27159</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I started running into this group mapping issue after update a client to 6.0.4. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a policy which matches on an Active Directory group for SSLVPN and what they can access. The same A.D. group is used in the Kerberos authentication profile to auth to VPN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the update, these users are no longer matching on this policy. There is a policy just above it utilizing a different A.D. group and users from that group match just fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did notice in the CLI if I do a show user group mapping ?, it lists the LDAP format of the group name as oppose to domain/group... whereas for the group which is working, it shows domain/group. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I go to the policy and delete the group then add the group back name in via the LDAP format, it auto-resolves it to the group\domain format as soon as I hit enter. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Aug 2014 00:51:32 GMT</pubDate>
    <dc:creator>SDorsey</dc:creator>
    <dc:date>2014-08-08T00:51:32Z</dc:date>
    <item>
      <title>6.0.4 group mapping issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/6-0-4-group-mapping-issue/m-p/37005#M27159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I started running into this group mapping issue after update a client to 6.0.4. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a policy which matches on an Active Directory group for SSLVPN and what they can access. The same A.D. group is used in the Kerberos authentication profile to auth to VPN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the update, these users are no longer matching on this policy. There is a policy just above it utilizing a different A.D. group and users from that group match just fine. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did notice in the CLI if I do a show user group mapping ?, it lists the LDAP format of the group name as oppose to domain/group... whereas for the group which is working, it shows domain/group. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I go to the policy and delete the group then add the group back name in via the LDAP format, it auto-resolves it to the group\domain format as soon as I hit enter. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2014 00:51:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/6-0-4-group-mapping-issue/m-p/37005#M27159</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-08-08T00:51:32Z</dc:date>
    </item>
    <item>
      <title>Re: 6.0.4 group mapping issue?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/6-0-4-group-mapping-issue/m-p/37006#M27160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Eureka. Apparently 6.0.4 may have a problem processing group names which have a hyphen. I create a new group with the same users which lacked a hyphen and it matched as expected. Added a hyphen to the new group and it stopped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Aug 2014 01:11:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/6-0-4-group-mapping-issue/m-p/37006#M27160</guid>
      <dc:creator>SDorsey</dc:creator>
      <dc:date>2014-08-08T01:11:48Z</dc:date>
    </item>
  </channel>
</rss>

