<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Authentication Profile update for VPN User-ID mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69405#M40281</link>
    <description>&lt;P&gt;I already tunning update interval to 60 Second and it's works for my user-id group in security policy but somehow it's not working in my user-id group on Global Protect. There is another way ?&lt;/P&gt;</description>
    <pubDate>Sat, 12 Dec 2015 04:17:41 GMT</pubDate>
    <dc:creator>gabriel.simatupang</dc:creator>
    <dc:date>2015-12-12T04:17:41Z</dc:date>
    <item>
      <title>User Authentication Profile update for VPN User-ID mapping PANOS 7.0.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69360#M40268</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have problem in my VPN user Identification (they cannot login to portal) after there's update/change in my AD server group. I already doing this &lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Force-User-Group-Mapping-Refresh/ta-p/62597" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Force-User-Group-Mapping-Refresh/ta-p/62597&lt;/A&gt; to force user group mapping refresh. It's work to update my User-ID in my policy but my VPN User mapping still not updated untill almost 60 minutes. There is any way to refresh/tunning or Query it faster to update VPN user mapping?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 06:04:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69360#M40268</guid>
      <dc:creator>gabriel.simatupang</dc:creator>
      <dc:date>2016-07-18T06:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: User Authentication Profile update for VPN User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69362#M40269</link>
      <description>&lt;P&gt;Hi Gabriel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Have you set an allow list in the authentication profile itself? If not the issue may be a connectivity issue between the firewall and the ldap server instead of group mapping&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can change the group mapping update interval in the group mapping object :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Device &amp;gt; User Identification&amp;gt; Group Mapping Settings &amp;gt; Server Profile &amp;gt; Update Interval&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1591i3E9AA7CDE0158C61/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="group mapping" title="group mapping" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you're aware a change was made you can also trigger a manual update from the CLI:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug user-id refresh group-mapping all&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 11:39:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69362#M40269</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-12-11T11:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: User Authentication Profile update for VPN User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69375#M40274</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/34490"&gt;@gabriel.simatupang﻿&lt;/a&gt;&amp;nbsp;The "Value" threshold of 60-86400 is in seconds I believe. &amp;nbsp;Your request to have the group refreshed more quickly than 60 minutes just means set this value below 3600 seconds, down to as low as 60 seconds. &amp;nbsp;Although, I'm not sure how much of an impact setting the refresh to 60 seconds would have on your firewall.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2015 16:28:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69375#M40274</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2015-12-11T16:28:49Z</dc:date>
    </item>
    <item>
      <title>Re: User Authentication Profile update for VPN User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69405#M40281</link>
      <description>&lt;P&gt;I already tunning update interval to 60 Second and it's works for my user-id group in security policy but somehow it's not working in my user-id group on Global Protect. There is another way ?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 04:17:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69405#M40281</guid>
      <dc:creator>gabriel.simatupang</dc:creator>
      <dc:date>2015-12-12T04:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: User Authentication Profile update for VPN User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69599#M40343</link>
      <description>&lt;P&gt;The group mapping for the security policies and the authentication in GP should be identical, since they both come from the same profile that is updated&lt;/P&gt;
&lt;P&gt;Unless ... are you using multiple ldap profiles ? (maybe one is being updated properly and the other isnt)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you increase debugging and tail the logs during authentication, does anything interesting pop up:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug authentication on debug
&amp;gt; tail follow yes mp-log authd.log&lt;/PRE&gt;
&lt;P&gt;you can try to take a look at the logging for user-id as well to see if anything might be failing:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug user-id on debug
&amp;gt; less mp-log authd.log&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 11:21:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/69599#M40343</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-12-17T11:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: User Authentication Profile update for VPN User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/98268#M44112</link>
      <description>&lt;P&gt;thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper﻿&lt;/a&gt; for your help. but after i open case to tac they said:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Engineering team has decided that this fix will not be added to 7.0 or 7.1 code versions due to the significant design changes involved in the fix. These design changes will be handled in 8.0 releases.&lt;/P&gt;&lt;P&gt;The workaround is to use "all" or individual users in the allow list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so i must wait PANOS 8 release. Do you have any idea when PANOS 8 release?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 06:03:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/98268#M44112</guid>
      <dc:creator>gabriel.simatupang</dc:creator>
      <dc:date>2016-07-18T06:03:36Z</dc:date>
    </item>
    <item>
      <title>Re: User Authentication Profile update for VPN User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/98272#M44115</link>
      <description>&lt;P&gt;I would guess, based on previous release timeframes of about 8-10 months between major releases,&amp;nbsp;that PAN-OS 8.0 is likely to appear around the end of this year. But currently there's nothing out yet so I'd advise you to keep checking in regularly. Once 8.0 is about to be released you should see announcements popping up&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2016 06:57:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-authentication-profile-update-for-vpn-user-id-mapping-panos/m-p/98272#M44115</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-07-18T06:57:15Z</dc:date>
    </item>
  </channel>
</rss>

