<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Panorama LDAP group mappings not updating for user-id in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-ldap-group-mappings-not-updating-for-user-id/m-p/72693#M41157</link>
    <description>&lt;P&gt;The issue is as by design the panorama device is not intergrated with AD (the is a Feature Request for this).&lt;/P&gt;
&lt;P&gt;Here is the following proceedure that needs to be done for new AD groups being added to a policy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the user-id tab of the policy rule, click add and paste the entire tree directory mapping to the new AD group:&lt;/P&gt;
&lt;P&gt;Example: cn=admin,ou=stuff,ou=more_stuff,ou=even_more_stuff,ou=bigger_stuff,ou=organizational units,dc=ds,dc=company,dc=com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will see it will map and change to the short version company\stuff…blah blah blah…&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don’t know what the full mapping is or your too lazy to type it all out…do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Login to any gateway CLI and do the following command: show user group list | match stuff&amp;nbsp;*&lt;STRONG&gt;or whatever the name is&lt;/STRONG&gt;*&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will get the following output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@Test-FW01(active)&amp;gt; show user group list&amp;nbsp; | match stuff&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;cn=&lt;/SPAN&gt;&lt;SPAN&gt;admin&lt;/SPAN&gt;&lt;SPAN&gt;,ou=&lt;/SPAN&gt;&lt;SPAN&gt;stuff&lt;/SPAN&gt;&lt;SPAN&gt;,ou=&lt;/SPAN&gt;&lt;SPAN&gt;more_stuff&lt;/SPAN&gt;&lt;SPAN&gt;,ou=&lt;/SPAN&gt;&lt;SPAN&gt;even_more_stuff&lt;/SPAN&gt;&lt;SPAN&gt;,ou=bigger_stuff,ou=organizational units,dc=ds,dc=company,dc=com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 11 Feb 2016 15:32:56 GMT</pubDate>
    <dc:creator>Gun-Slinger</dc:creator>
    <dc:date>2016-02-11T15:32:56Z</dc:date>
    <item>
      <title>Panorama LDAP group mappings not updating for user-id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-ldap-group-mappings-not-updating-for-user-id/m-p/72085#M40996</link>
      <description>&lt;P&gt;We have user-id setup and every cluster with a designated master device for user-id mappings. I have the group mapping of the new AD group showing in the gateway itself, however when I go to implement the group in a policy in panorama, it will not display the new group. I have done a forced refresh on the gateway and refreshed the panorama but with no luck. It will still not display the new AD group created....any idea?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 16:30:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-ldap-group-mappings-not-updating-for-user-id/m-p/72085#M40996</guid>
      <dc:creator>Gun-Slinger</dc:creator>
      <dc:date>2016-02-03T16:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama LDAP group mappings not updating for user-id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-ldap-group-mappings-not-updating-for-user-id/m-p/72096#M40997</link>
      <description>&lt;P&gt;On panorama we have to manually enter the group/users in policies automatic is not done.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2016 18:56:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-ldap-group-mappings-not-updating-for-user-id/m-p/72096#M40997</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2016-02-03T18:56:12Z</dc:date>
    </item>
    <item>
      <title>Re: Panorama LDAP group mappings not updating for user-id</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/panorama-ldap-group-mappings-not-updating-for-user-id/m-p/72693#M41157</link>
      <description>&lt;P&gt;The issue is as by design the panorama device is not intergrated with AD (the is a Feature Request for this).&lt;/P&gt;
&lt;P&gt;Here is the following proceedure that needs to be done for new AD groups being added to a policy:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the user-id tab of the policy rule, click add and paste the entire tree directory mapping to the new AD group:&lt;/P&gt;
&lt;P&gt;Example: cn=admin,ou=stuff,ou=more_stuff,ou=even_more_stuff,ou=bigger_stuff,ou=organizational units,dc=ds,dc=company,dc=com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will see it will map and change to the short version company\stuff…blah blah blah…&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don’t know what the full mapping is or your too lazy to type it all out…do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Login to any gateway CLI and do the following command: show user group list | match stuff&amp;nbsp;*&lt;STRONG&gt;or whatever the name is&lt;/STRONG&gt;*&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will get the following output:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;admin@Test-FW01(active)&amp;gt; show user group list&amp;nbsp; | match stuff&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;cn=&lt;/SPAN&gt;&lt;SPAN&gt;admin&lt;/SPAN&gt;&lt;SPAN&gt;,ou=&lt;/SPAN&gt;&lt;SPAN&gt;stuff&lt;/SPAN&gt;&lt;SPAN&gt;,ou=&lt;/SPAN&gt;&lt;SPAN&gt;more_stuff&lt;/SPAN&gt;&lt;SPAN&gt;,ou=&lt;/SPAN&gt;&lt;SPAN&gt;even_more_stuff&lt;/SPAN&gt;&lt;SPAN&gt;,ou=bigger_stuff,ou=organizational units,dc=ds,dc=company,dc=com&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2016 15:32:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/panorama-ldap-group-mappings-not-updating-for-user-id/m-p/72693#M41157</guid>
      <dc:creator>Gun-Slinger</dc:creator>
      <dc:date>2016-02-11T15:32:56Z</dc:date>
    </item>
  </channel>
</rss>

