<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I disable a user on ldap ,but he can access the destination as before in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43600#M31997</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1238" data-externalid="" data-presence="null" data-userid="24719" data-username="ChuanhouLei" href="https://live.paloaltonetworks.com/people/ChuanhouLei"&gt;ChuanhouLei&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;PaloAlto Networks firewall when configured for group mapping,will talk to active directory every 60 minutes by default This is configurable under group mapping settings,update interval.&lt;/P&gt;&lt;P&gt;Once every 60 minutes (by default) an LDAP querry is sent to retrieve any changes or additions or deletions to user-group membership.Looks like you are seeing the issue where even when you removed the user from group from AD it is still not updating mapping on the Device and user can still access the website.&lt;/P&gt;&lt;P&gt;Try changing the update interval to 60 seconds and check if that resolved the issue.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Yashwanth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Jan 2014 16:30:31 GMT</pubDate>
    <dc:creator>ybommakanti</dc:creator>
    <dc:date>2014-01-03T16:30:31Z</dc:date>
    <item>
      <title>I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43599#M31996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;there have a user on the ldap , I allow he access one website in security policy .But when I disable this account on ldap srver , he can access the website as before , what can i do ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;消息编辑者为：Achates Ray&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 06:56:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43599#M31996</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-01-03T06:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43600#M31997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN class="j-post-author"&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link" data-avatarid="1238" data-externalid="" data-presence="null" data-userid="24719" data-username="ChuanhouLei" href="https://live.paloaltonetworks.com/people/ChuanhouLei"&gt;ChuanhouLei&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;PaloAlto Networks firewall when configured for group mapping,will talk to active directory every 60 minutes by default This is configurable under group mapping settings,update interval.&lt;/P&gt;&lt;P&gt;Once every 60 minutes (by default) an LDAP querry is sent to retrieve any changes or additions or deletions to user-group membership.Looks like you are seeing the issue where even when you removed the user from group from AD it is still not updating mapping on the Device and user can still access the website.&lt;/P&gt;&lt;P&gt;Try changing the update interval to 60 seconds and check if that resolved the issue.&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;Yashwanth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 16:30:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43600#M31997</guid>
      <dc:creator>ybommakanti</dc:creator>
      <dc:date>2014-01-03T16:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43601#M31998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your reply!&lt;/P&gt;&lt;P&gt;I am disable the user not delete or remove it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 05 Jan 2014 05:02:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43601#M31998</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-01-05T05:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43602#M31999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/10360"&gt;ybommakanti&lt;/A&gt;&lt;A href="https://live.paloaltonetworks.com/u1/1"&gt;admin&lt;/A&gt;I disable the user on ldap not remove the user,who can help me ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2014 09:48:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43602#M31999</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-07T09:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43603#M32000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;If the security policy is configured with the group that user is member of, it is expected to match security policy Firewall retrieve the AD groups and the associated members from ldap and keeps the group membership . If the user still exist in the group and there is a ipaddress to user mapping for that user account , you will see the from that user/ip is matching to the security rule You can try removing the user from the group in AD and Force User Group Mapping Refresh ( &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="3294" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3294"&gt;https://live.paloaltonetworks.com/docs/DOC-3294&lt;/A&gt;&lt;SPAN&gt;). See if that fix the issue .&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Mar 2014 15:51:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43603#M32000</guid>
      <dc:creator>knarra1</dc:creator>
      <dc:date>2014-03-08T15:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43604#M32001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you ,&lt;A href="https://live.paloaltonetworks.com/u1/18130"&gt;knarra1&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;If I want to filter some users, how should I do?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 03:00:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43604#M32001</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-10T03:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43605#M32002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are referring to users in group, We do not have option of filtering certain members in group. Please let me know if you are referring to something else&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 22:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43605#M32002</guid>
      <dc:creator>knarra1</dc:creator>
      <dc:date>2014-03-10T22:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43606#M32003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might be running into the following scenario during your testing. Please refer to this doc.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4534"&gt;Enable Age-Out Timeout With Netbios/WMI Disabled for User-ID Agent&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Below is another document for related symptoms&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4971"&gt;User-ID Does Not Send WMI Probes for Known IP Addresses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can also check out the following doc for detailed information&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;on user id &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1807"&gt;User Identification Tech Note - PAN-OS 4.0&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3120"&gt;User Identification Tech Note PAN-OS 4.1&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Let is know if this helps,&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Numan &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Mar 2014 23:54:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43606#M32003</guid>
      <dc:creator>mbutt</dc:creator>
      <dc:date>2014-03-10T23:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: I disable a user on ldap ,but he can access the destination as before</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43607#M32004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="useraccountcontrol.jpg" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/12104_useraccountcontrol.jpg" style="width: 620px; height: 476px;" /&gt;&lt;/P&gt;&lt;P&gt;I want to know how to set the Search Filter?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Mar 2014 10:44:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/i-disable-a-user-on-ldap-but-he-can-access-the-destination-as/m-p/43607#M32004</guid>
      <dc:creator>ChuanhouLei</dc:creator>
      <dc:date>2014-03-13T10:44:04Z</dc:date>
    </item>
  </channel>
</rss>

