<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't Get AD groups to be used as user authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-groups-to-be-used-as-user-authentication/m-p/50063#M36847</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue might be with the format that ldap is pulling up the user as. The agent might be pulling up the user as xx/user1 whereas ldap might pull it up as yy/user1. Can you verify if the user is mapped the same from both the agent and ldap?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. show user user-IDs match-user &amp;lt;user_name&amp;gt; : this is the one pulled by ldap&lt;/P&gt;&lt;P&gt;2. show user ip-user-mapping ip &amp;lt;ip_test_user&amp;gt; : this is per the agent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the output of 1 and 2 are different, goto the ldap server profile settings and change the domain to the one listed in 2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if this was helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Jul 2012 00:31:44 GMT</pubDate>
    <dc:creator>zarina</dc:creator>
    <dc:date>2012-07-31T00:31:44Z</dc:date>
    <item>
      <title>Can't Get AD groups to be used as user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-groups-to-be-used-as-user-authentication/m-p/50061#M36845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are running 2 2050 firewalls running 4.16 software and 2 user agents running 4.1.0-43 code.&amp;nbsp;&amp;nbsp; When i try to limit a policy by an AD user name it works fine.&amp;nbsp;&amp;nbsp; However if I want to user a AD group name it wont hit the rule if i put in the user as a group.&amp;nbsp; What am i doing wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So&lt;/P&gt;&lt;P&gt;MYAD\mcarlton will work for a user on a policy but&lt;/P&gt;&lt;P&gt;MYAD\cooladmins will not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am i doing wrong?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2012 16:51:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-groups-to-be-used-as-user-authentication/m-p/50061#M36845</guid>
      <dc:creator>mcarlton</dc:creator>
      <dc:date>2012-07-26T16:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Get AD groups to be used as user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-groups-to-be-used-as-user-authentication/m-p/50062#M36846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just some ideas, as I'm currently also playing with this feature set:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;have you included the ou where the groups are in into the group mappings? (Device --&amp;gt; User Identication" --&amp;gt; Group Mappings")&lt;/LI&gt;&lt;LI&gt;have you limited the LDAP Server into a Base DN where the groups are not included?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andre&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Jul 2012 16:56:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-groups-to-be-used-as-user-authentication/m-p/50062#M36846</guid>
      <dc:creator>u13550</dc:creator>
      <dc:date>2012-07-26T16:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Get AD groups to be used as user authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-groups-to-be-used-as-user-authentication/m-p/50063#M36847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue might be with the format that ldap is pulling up the user as. The agent might be pulling up the user as xx/user1 whereas ldap might pull it up as yy/user1. Can you verify if the user is mapped the same from both the agent and ldap?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. show user user-IDs match-user &amp;lt;user_name&amp;gt; : this is the one pulled by ldap&lt;/P&gt;&lt;P&gt;2. show user ip-user-mapping ip &amp;lt;ip_test_user&amp;gt; : this is per the agent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the output of 1 and 2 are different, goto the ldap server profile settings and change the domain to the one listed in 2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know if this was helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 00:31:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-get-ad-groups-to-be-used-as-user-authentication/m-p/50063#M36847</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-07-31T00:31:44Z</dc:date>
    </item>
  </channel>
</rss>

