<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Removed user from a AD group still given the access in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37144#M27248</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done a scheduled CLI for "clear session all", and that not solve my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last things i can test is reboot PA or i will open a ticket.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Oct 2012 14:29:20 GMT</pubDate>
    <dc:creator>denisgaron</dc:creator>
    <dc:date>2012-10-05T14:29:20Z</dc:date>
    <item>
      <title>Removed user from a AD group still given the access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37140#M27244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So here my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have create a new rule with a&amp;nbsp; new AD group.&amp;nbsp; I have added 4 users in the group, including myself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have open a new custom URL group there.&amp;nbsp; All work fine so far.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here my problem.&amp;nbsp; I try to remove myself from the group.&amp;nbsp; After applied many time rules, i still have an access to this rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I have remove myself from that AD group.&lt;/P&gt;&lt;P&gt;- then i do the command CLI : show user group name "the_group".&amp;nbsp; Its show 3 users (myself remove from the list).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So by apply rule its should remove my access.&amp;nbsp; But when i check "MONITOR" i still see i get access for that rule.&amp;nbsp; PA CLI no see me in the group but PA still have me listed in the AD GROUP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not use&amp;nbsp; "Group Mapping Settings" in "Device&amp;gt;User identification"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead i have list the AD group right in the policies, in USER TAB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clue? how many time PA will take to sync the AD groups?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2012 17:32:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37140#M27244</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-10-01T17:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: Removed user from a AD group still given the access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37141#M27245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just for interest sake try flushing the session table and retest - "clear session all"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2012 20:29:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37141#M27245</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2012-10-01T20:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Removed user from a AD group still given the access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37142#M27246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As said above you can try clearing sessions. You can clear the sessions belonging to your PC by command "clear session all filter source 'PC IP address' " that way you do not interrupt other sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Oct 2012 22:11:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37142#M27246</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-10-01T22:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: Removed user from a AD group still given the access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37143#M27247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so far i have try what sdurga say, because clear all session can have some behvior to others users. But i will try tonight to clear all sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But that not solve the problem.&amp;nbsp; I still have access since 2 days even is im not in the AD group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just one command have have remove me access just for like 1 minute :&lt;/P&gt;&lt;P&gt;-&amp;nbsp; clear session all filter rule "The_rule_that_give_me_wrong_access"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that clear, my sessions wasnt authentificated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Monitor i was seeing myself access with an IP.&amp;nbsp; Its take like 1 minute before see authentificated access back with my username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right after, i get by my back my wrong access like before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So clear the users cache not seam to remove my access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Oct 2012 14:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37143#M27247</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-10-03T14:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: Removed user from a AD group still given the access</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37144#M27248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have done a scheduled CLI for "clear session all", and that not solve my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Last things i can test is reboot PA or i will open a ticket.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Oct 2012 14:29:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/removed-user-from-a-ad-group-still-given-the-access/m-p/37144#M27248</guid>
      <dc:creator>denisgaron</dc:creator>
      <dc:date>2012-10-05T14:29:20Z</dc:date>
    </item>
  </channel>
</rss>

