<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TIP:  LDAP Group Mappings in a mixed 6.x and 7.x environment with Panorama in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/tip-ldap-group-mappings-in-a-mixed-6-x-and-7-x-environment-with/m-p/64728#M38753</link>
    <description>&lt;P&gt;This is very useful feedback from the field. Thank you !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am actually curious : did you create a TAC case ? IMO it should be highlighted as a bug , a mechanism should be in place to support PANOS 6.0&amp;lt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Sep 2015 09:09:41 GMT</pubDate>
    <dc:creator>cpainchaud</dc:creator>
    <dc:date>2015-09-17T09:09:41Z</dc:date>
    <item>
      <title>TIP:  LDAP Group Mappings in a mixed 6.x and 7.x environment with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tip-ldap-group-mappings-in-a-mixed-6-x-and-7-x-environment-with/m-p/64701#M38742</link>
      <description>&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought I would share a quick tip for those people that may be considering upgrading from 6.x to 7.x in an environment where you are using Panorama.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In PAN-OS 7.x, the information of your Active Directory domain has been moved from the LDAP settings to the Group Mapping Settings. As the first step in upgrading to 7.x is upgrading your Panorama server, you will immediately notice that this field is no longer available in the template.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/361i10C528B758D7CE50/image-size/large?v=mpbl-1&amp;amp;px=-1" border="0" alt="Panorama Template.png" title="Panorama Template.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;This setting has been moved to Group Mappings:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/363i3E9EBF73835DE4FD/image-size/large?v=mpbl-1&amp;amp;px=-1" border="0" alt="Group Mapping.png" title="Group Mapping.png" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you push this template to any devices that are running PAN-OS 6.x, the domain field in the LDAP settings will become empty&amp;nbsp;which can cause your users in groups to return the wrong mapping without the domain. &amp;nbsp;In our case, it caused the following to happen:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;User-ID&lt;/U&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;--------------- ------ ------- -------------------------------- -------------- -------------&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;X.X.X.X &amp;nbsp; &amp;nbsp; vsys1 &amp;nbsp;UIA &amp;nbsp; &amp;nbsp; &amp;lt;domain&amp;gt;\mlinsemier &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;40 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 40&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;Group Mapping:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;short name: &amp;lt;domain&amp;gt;\pan-downloads-it&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;source type: proxy&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;source: Group Mapping - Domain&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[1 ] \mlinsemier&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[2 ]&amp;nbsp;\jsmith&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[3 ]&amp;nbsp;\jdoe&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will notice that the user names in the Group Mapping are missing the domain portion. &amp;nbsp;This causes any rules that you have setup based on groups not to map correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To fix the issue, you must push your template and then create a local override on each PAN-OS 6.x firewall for each LDAP group and enter&amp;nbsp;your domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/362i83A10BA3D9CE149A/image-size/large?v=mpbl-1&amp;amp;px=-1" border="0" alt="Firewall Domain.png" title="Firewall Domain.png" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One thing also to note is that when you upgrade a firewall to&amp;nbsp;PAN-OS 7.x, Panorama may still show that your Templates &amp;nbsp;for that devife a re still '"in Sync" after the upgrade. &amp;nbsp;We didn't re-push the templates after the upgrade&amp;nbsp;to our PAN-OS 7.x firewalls, which meant that the domain field in Group Mapping was blank and caused the same issues. &amp;nbsp;Once we pushed them, the information was populated from the template and all was fixed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought I would share this just in case others are in a similar boat as we were. &amp;nbsp;YMMV.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 16:53:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tip-ldap-group-mappings-in-a-mixed-6-x-and-7-x-environment-with/m-p/64701#M38742</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2015-09-16T16:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: TIP:  LDAP Group Mappings in a mixed 6.x and 7.x environment with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tip-ldap-group-mappings-in-a-mixed-6-x-and-7-x-environment-with/m-p/64728#M38753</link>
      <description>&lt;P&gt;This is very useful feedback from the field. Thank you !!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am actually curious : did you create a TAC case ? IMO it should be highlighted as a bug , a mechanism should be in place to support PANOS 6.0&amp;lt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 09:09:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tip-ldap-group-mappings-in-a-mixed-6-x-and-7-x-environment-with/m-p/64728#M38753</guid>
      <dc:creator>cpainchaud</dc:creator>
      <dc:date>2015-09-17T09:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: TIP:  LDAP Group Mappings in a mixed 6.x and 7.x environment with Panorama</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/tip-ldap-group-mappings-in-a-mixed-6-x-and-7-x-environment-with/m-p/64737#M38758</link>
      <description>&lt;P&gt;This actually surfaced as two different TAC cases, Panorama 7.x with PAN-OS 6.x clients and PAN-OS 7.x Group Mappings not working. &amp;nbsp;We had both of them open at the same time (was waiting for more troubleshooting for the initial case), when through troubleshooting myself it dawned on me what was happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did ask TAC to forward this to engineering and also sent this up to my Palo Alto SE to ask him to create a bug for this. &amp;nbsp;In a mixed environment, Panorama will need to know the PAN-OS to determine now to configure LDAP and Group Mapping, which right now I don't know if this is possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyways, glad it was helpful. &amp;nbsp;I love the Palo Alto product and figured if I can give back to the community to save at least one other engineer hours of troubleshooting, it's a good thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Thu, 17 Sep 2015 13:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/tip-ldap-group-mappings-in-a-mixed-6-x-and-7-x-environment-with/m-p/64737#M38758</guid>
      <dc:creator>mlinsemier</dc:creator>
      <dc:date>2015-09-17T13:26:34Z</dc:date>
    </item>
  </channel>
</rss>

