<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID domain-map in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69219#M40209</link>
    <description>&lt;P&gt;Have you added group mapping under user-identification?&lt;/P&gt;</description>
    <pubDate>Tue, 08 Dec 2015 21:22:42 GMT</pubDate>
    <dc:creator>pankaku</dc:creator>
    <dc:date>2015-12-08T21:22:42Z</dc:date>
    <item>
      <title>User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69213#M40204</link>
      <description>&lt;P&gt;Hi guys.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a problem with a user-id setup in a large multi domain envoirment. User-ID agentd are working fine, but the user did not match against the group mapping. It looks like we have a problem with the domain map. The command debug user-id dump domain-map delivers only a empty result. We setup the group maping against the Global Catalog of the root domain.&lt;/P&gt;
&lt;P&gt;Does anyone know which attribute Palo Alto Networks read out of the AD for the domain-map? Maybe there is an issue withe the AD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards, Markus&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 20:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69213#M40204</guid>
      <dc:creator>markuskohlmeier</dc:creator>
      <dc:date>2015-12-08T20:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69215#M40205</link>
      <description>&lt;P&gt;Check these DOC's&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Group-Mapping-in-a-Multi-Domain-Active/ta-p/60784" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Group-Mapping-in-a-Multi-Domain-Active/ta-=p/60784&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/Correct-Group-and-IP-to-User-Mapping-in-Multi-domain-AD-Forest/ta-p/55505" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/Correct-Group-and-IP-to-User-Mapping-in-Multi-domain-AD-Forest/ta-p/55505&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Group-Mapping-for-Users-in-Multiple-Domains/ta-p/62089" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Group-Mapping-for-Users-in-Multiple-Domains/ta-p/62089&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/IP-to-User-Mappings-Have-Inconsistent-Domain-Prefix/ta-p/59351" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/IP-to-User-Mappings-Have-Inconsistent-Domain-Prefix/ta-p/59351&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 20:50:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69215#M40205</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-08T20:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69217#M40207</link>
      <description>&lt;P&gt;Hi pakumar.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know all these documents and I configured it as usual (and as described in the documents). But without success. I think my problem is the domain-map, because it should not be empty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards, Markus&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:04:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69217#M40207</guid>
      <dc:creator>markuskohlmeier</dc:creator>
      <dc:date>2015-12-08T21:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69219#M40209</link>
      <description>&lt;P&gt;Have you added group mapping under user-identification?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:22:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69219#M40209</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-08T21:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69220#M40210</link>
      <description>&lt;P&gt;Yes, of course.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:23:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69220#M40210</guid>
      <dc:creator>markuskohlmeier</dc:creator>
      <dc:date>2015-12-08T21:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69221#M40211</link>
      <description>&lt;P&gt;Hi. Just to be clear, I setup user-id, also in large envoirments, several times successful. But this time I have problems with the group mapping respectively the domain-map. So it would be interesting if anyone know which AD attribute or value Palo Alto Network use as domain-map.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you and best regards, Markus&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69221#M40211</guid>
      <dc:creator>markuskohlmeier</dc:creator>
      <dc:date>2015-12-08T21:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69222#M40212</link>
      <description>&lt;P&gt;Okay try one more think change the domain name to netbios-name and test.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:32:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69222#M40212</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-12-08T21:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69223#M40213</link>
      <description>&lt;P&gt;Hi. I tried that allready, without success.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2015 21:33:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69223#M40213</guid>
      <dc:creator>markuskohlmeier</dc:creator>
      <dc:date>2015-12-08T21:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID domain-map</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69237#M40221</link>
      <description>&lt;P&gt;Hi Markus,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you try this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Modify&amp;nbsp;the LDAP server profile to use port 636 for the connection to the GC.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. Create&amp;nbsp;a new group mapping using this LDAP profile.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3. Use one group from the group list pulled from the server and put it in include list and commit the changes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;See if it helps. Else I would suggest to contact support.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Abhishek&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 02:51:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-domain-map/m-p/69237#M40221</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2015-12-09T02:51:41Z</dc:date>
    </item>
  </channel>
</rss>

