<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User mapped via CLI but no through Web-UI in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45394#M33363</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ip-user mapping is received through the agent. If you need to use groups/users in the policy make sure to configure group mapping on the device: Device -&amp;gt; User Identification -&amp;gt; Group Mapping Settings&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Jul 2013 17:05:34 GMT</pubDate>
    <dc:creator>zarina</dc:creator>
    <dc:date>2013-07-03T17:05:34Z</dc:date>
    <item>
      <title>User mapped via CLI but no through Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45393#M33362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to configure an user in a security policy but when I write the first 4 letters of his username it doesn't appear (screenshoot attached). However, it does appear throug CLI:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;admin@PA1(active)&amp;gt; show user ip-user-mapping all | match mmlu&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;10.161.34.189&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp; UIA&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; idc\mmluque&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3516&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3516&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clue about the problem?.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks so much,&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 14:31:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45393#M33362</guid>
      <dc:creator>COMIP</dc:creator>
      <dc:date>2013-07-03T14:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: User mapped via CLI but no through Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45394#M33363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The ip-user mapping is received through the agent. If you need to use groups/users in the policy make sure to configure group mapping on the device: Device -&amp;gt; User Identification -&amp;gt; Group Mapping Settings&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 17:05:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45394#M33363</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2013-07-03T17:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: User mapped via CLI but no through Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45395#M33364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;debug user-id refresh dp-uid-gid&lt;/P&gt;&lt;P&gt;debug user-id refresh group-mapping all&lt;/P&gt;&lt;P&gt;debug user-id refresh user-id agent all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you try these.how many DC do you have in LDAP profile ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 17:51:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45395#M33364</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-07-03T17:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: User mapped via CLI but no through Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45396#M33365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answers. Today the user didn't appear neither CLI nor web-ui. Tomorrow I'll try it again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@panos, in my LDAP profile I have 4 servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Jul 2013 15:50:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45396#M33365</guid>
      <dc:creator>COMIP</dc:creator>
      <dc:date>2013-07-04T15:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: User mapped via CLI but no through Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45397#M33366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I launched the 3 commands but the problem persists, I see the user through CLI but not in web-ui.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 09:42:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45397#M33366</guid>
      <dc:creator>COMIP</dc:creator>
      <dc:date>2013-07-08T09:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: User mapped via CLI but no through Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45398#M33367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Comip,&lt;/P&gt;&lt;P&gt;It appears that there is a mismatch between the group names that is being fetched from the agent, and from the firewall when it talks directly to the LDAP server for group mapping. Do you have any "Domain" name configured under the LDAP server settings? If so, can we delete the domain name and commit the changes, and see if it makes a difference?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;/P&gt;&lt;P&gt;Karthik RP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 12:54:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45398#M33367</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-07-08T12:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: User mapped via CLI but no through Web-UI</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45399#M33368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the domain 'idc' configured in 'Domain' field. I manage Palo Alto through Global Protect VPN authenticated through LDAP and if I delete the idc in that field, I am not be able to authenticate through Global Protect, my user appears as 'invalid user'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 13:00:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-mapped-via-cli-but-no-through-web-ui/m-p/45399#M33368</guid>
      <dc:creator>COMIP</dc:creator>
      <dc:date>2013-07-08T13:00:23Z</dc:date>
    </item>
  </channel>
</rss>

