<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user-ID user mapping problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/41857#M30792</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the group errors;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the LDAP config, under active directory name, make sure this setting is in NETBIOS format not DNS name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg DOMAINNAME and not domainname.com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 20 Nov 2011 06:08:38 GMT</pubDate>
    <dc:creator>supportOCA</dc:creator>
    <dc:date>2011-11-20T06:08:38Z</dc:date>
    <item>
      <title>user-ID user mapping problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/41856#M30791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Our PA 4.1 has problems mapping entries received from user-ID agent and LDAP queries.&lt;/P&gt;&lt;P&gt;show user ip-user-mapping command produces following output:&lt;/P&gt;&lt;P&gt;192.168.1.1 AD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; grybai\vltr12345678 &lt;/P&gt;&lt;P&gt;Here grybai is our NetBIOS domain name for domain and&amp;nbsp; vltr12345678 is sAMAccountName attribute of user object in LDAP.&lt;/P&gt;&lt;P&gt;However command show user user-IDs (which shows information received by PA from LDAP queries) for the same user shows:&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:tadas.blinda@grybaiagrupe.eu"&gt;tadas.blinda@grybaiagrupe.eu&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp; cn=b8710 users,ou=email,ou=groups,dc=corp,dc=grybaigroup,dc=eu&lt;/P&gt;&lt;P&gt;where &lt;A href="mailto:tadas.blinda@grybaiagrupe.eu"&gt;tadas.blinda@grybaiagrupe.eu&lt;/A&gt; is userPrincipalName attribute for the same user.&lt;/P&gt;&lt;P&gt;During policy configuration PA web interface gives list of users in &lt;A href="mailto:tadas.blinda@grybaiagrupe.eu"&gt;tadas.blinda@grybaiagrupe.eu&lt;/A&gt; , however such policy doesn't match traffic for that user. Policy with group also doesn't match traffic for that user.&lt;/P&gt;&lt;P&gt;If add policy with grybai\vltr12345678 user (I have to manually type user name during policy configuration), it matches traffic for that user.&lt;/P&gt;&lt;P&gt;LDAP server is configured as type active-directory, under "Group mapping settings" username field is configured as sAMAccountName (default). Tried to change that value with no lock.&lt;/P&gt;&lt;P&gt;Any ideas how to fix it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Nov 2011 07:40:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/41856#M30791</guid>
      <dc:creator>SimasK</dc:creator>
      <dc:date>2011-11-18T07:40:59Z</dc:date>
    </item>
    <item>
      <title>Re: user-ID user mapping problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/41857#M30792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the group errors;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the LDAP config, under active directory name, make sure this setting is in NETBIOS format not DNS name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;eg DOMAINNAME and not domainname.com&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Nov 2011 06:08:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/41857#M30792</guid>
      <dc:creator>supportOCA</dc:creator>
      <dc:date>2011-11-20T06:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: user-ID user mapping problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/41858#M30793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the User-ID_Upgrade_4.1 it is quite clearly noted not configure any domain unless device is working in multidomain environment, so we don't configured any. Before posting this post I tried to configure both netbios and dns domains without any luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Nov 2011 15:54:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/41858#M30793</guid>
      <dc:creator>SimasK</dc:creator>
      <dc:date>2011-11-21T15:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: user-ID user mapping problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/218530#M63162</link>
      <description>&lt;P&gt;Did You resolve this issue? I have same problem..&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 12:49:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-user-mapping-problems/m-p/218530#M63162</guid>
      <dc:creator>Interface</dc:creator>
      <dc:date>2018-06-20T12:49:50Z</dc:date>
    </item>
  </channel>
</rss>

