<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot find AD group in &amp;quot;source user&amp;quot; tab in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113727#M45240</link>
    <description>&lt;P&gt;Panorama or firewall?&lt;/P&gt;</description>
    <pubDate>Thu, 15 Sep 2016 17:41:07 GMT</pubDate>
    <dc:creator>MangoTango</dc:creator>
    <dc:date>2016-09-15T17:41:07Z</dc:date>
    <item>
      <title>Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113664#M45237</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have added two new AD group, on DC.&lt;/P&gt;&lt;P&gt;I can clearly see them in group mapping setting:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Group_Mapping_OK.JPG" style="width: 630px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5596i4B50A52673ED5475/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Group_Mapping_OK.JPG" alt="Group_Mapping_OK.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While in "source user" tab:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Deny_internet_not_found.JPG" style="width: 411px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5598i30252482008D7F64/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Deny_internet_not_found.JPG" alt="Deny_internet_not_found.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What can cause this behavior? When the AD group will be available in "source user" find?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Suggestions?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 14:23:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113664#M45237</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-09-15T14:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113708#M45238</link>
      <description>&lt;P&gt;Luca,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you click the + sign to add the group to the 'Included Groups' section in the mapping?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 16:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113708#M45238</guid>
      <dc:creator>RFalconer</dc:creator>
      <dc:date>2016-09-15T16:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113727#M45240</link>
      <description>&lt;P&gt;Panorama or firewall?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 17:41:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113727#M45240</guid>
      <dc:creator>MangoTango</dc:creator>
      <dc:date>2016-09-15T17:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113853#M45247</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37340"&gt;@MangoTango﻿&lt;/a&gt;&amp;nbsp;Firewall!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32044"&gt;@RFalconer﻿&lt;/a&gt;&amp;nbsp;Other AD groups are available in "source user" find, even if they are not added&amp;nbsp;&lt;SPAN&gt;to the 'Included Groups' section in the mapping.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BR&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Luca&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 08:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113853#M45247</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-09-16T08:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113860#M45248</link>
      <description>&lt;P&gt;As this is a new group you have added, you might need to refresh the group mappings for the firewall to fetch them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id refresh group-mapping all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Worth a try.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if you input the group name manually rather than selecting it from a drop down, will this populate the policy with the group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 10:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113860#M45248</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-09-16T10:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113866#M45252</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried command you suggested:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;============================&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW01(active)&amp;gt; debug user-id refresh group-mapping all&lt;/P&gt;&lt;P&gt;group mapping 'Group_Map' in vsys1 is marked for refresh.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;============================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The problem it's not related with group mapping.. I suppose this because I can clearly see "denyinternet" AD group in "group mapping" but NOT in source user.. Also if I type "denyinternet" the "source user" tab cannot find anything related to this one.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tha's strange.. Maybe I missing something stupid.. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Let me know if you have something else.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Further PA uptime is 153 days.. I don't know maybe something that it's not working properly with process.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Probably I will try with rebooting the appliance (I know I can restart a single process but at this point.. )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Luca&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 13:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/113866#M45252</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-09-16T13:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/114106#M45279</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall has been reboteed an now seems it works fine.&lt;/P&gt;&lt;P&gt;But there is something that I don't understan on user-id refershing timeout.&lt;/P&gt;&lt;P&gt;I need to refresh cache related to the user gruop info, very quickly in order to permit or deny a specific traffic flow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This seems a problem, I have tried these commands but:&lt;/P&gt;&lt;P&gt;=========================================&lt;/P&gt;&lt;P&gt;FW01(active)&amp;gt; debug user-id refresh group-mapping all&lt;/P&gt;&lt;P&gt;group mapping 'Group_Map' in vsys1 is marked for refresh.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW01(active)&amp;gt; debug user-id refresh dp-uid-gid&lt;/P&gt;&lt;P&gt;Scheduled to refresh user groups info on DP for vsys 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clear the cache:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW01(active)&amp;gt; clear user-cache all&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;=========================================&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Nothing is changed (Why marked for refresh ??)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I need to refresh quickly user's group info and NOT MANUALLY, which is the correct cache/timeout that I need to modify?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If user's group info doesn't refresh in less then 2/3 minutes, this can cause a huge impact on the enviroment, because there are users that can surf the internet while other user NOT(associated whit "denyinternet" AD group).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1﻿&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37340"&gt;@MangoTango﻿&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/32044"&gt;@RFalconer﻿&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 08:11:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/114106#M45279</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-09-19T08:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/114107#M45280</link>
      <description>&lt;P&gt;Hi Luca,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The quickest you can change the group mapping refresh timer to be is 60 seconds. You can find this option under the group mapping settings. Running the group refresh command will get the device to refresh it quicker, why 'mark for refresh' I am not sure, maybe the device needs to finish processing what it is doing before it can begin the refresh, so marking it makes the user-id process finish the current task then run a refresh afterwards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're making lots of group changes on your AD then you could create a script to&amp;nbsp;open a CLI session and run this command. I have had a look and I don't think you can run debug commands via the&amp;nbsp;XML API, you can clear the user ID cache but not refresh the group mappings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;edit: the timer is 60 seconds, not 60 minutes.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 08:29:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/114107#M45280</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2016-09-19T08:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/114108#M45281</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will check again the configuration and I will update you asap..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 08:26:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/114108#M45281</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-09-19T08:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/115266#M45401</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have set the refresh timeout as you suggested.&lt;/P&gt;&lt;P&gt;I will do some test and I will verify if everything works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot,&lt;/P&gt;&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2016 10:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/115266#M45401</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-09-22T10:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot find AD group in "source user" tab</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/116010#M45445</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5403"&gt;@bmorris1﻿&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Set timeout to 60 sec, everything works fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;Luca&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2016 12:24:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cannot-find-ad-group-in-quot-source-user-quot-tab/m-p/116010#M45445</guid>
      <dc:creator>TheRealDiz</dc:creator>
      <dc:date>2016-09-26T12:24:22Z</dc:date>
    </item>
  </channel>
</rss>

