<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 4.1.7 Problem with Domain Users enumeration persists. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-problem-with-domain-users-enumeration-persists/m-p/6783#M4977</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Support did resolve the issue.&amp;nbsp; Apparently there are multiple ways to setup the domain, and one way works better than the other.&amp;nbsp; Basically, create only one LDAP mapping per domain, and then import all the groups you desire through the single mapping.&amp;nbsp; Do not create a single mapping per LDAP group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 29 Oct 2012 19:51:45 GMT</pubDate>
    <dc:creator>EdwinD</dc:creator>
    <dc:date>2012-10-29T19:51:45Z</dc:date>
    <item>
      <title>4.1.7 Problem with Domain Users enumeration persists.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-problem-with-domain-users-enumeration-persists/m-p/6781#M4975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am running PanOS 4.1.7 on a pair of HA 2050's which use direct LDAP connectivity to multiple AD servers for group membership.&amp;nbsp;&amp;nbsp; I also have the UaInstall-4.1.5-1.MSI 4.1.5 user to IP agents running on my DCs.&amp;nbsp; I do not have the group membership coming from the user to IP agent running on the servers.&amp;nbsp; I have the 2050's enumerating group membership directly from the AD LDAP servers, using the global connection port 5007 from the Firewall to the AD servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I upgrade from 4.1.5 to 4.1.7 because I am aware of the known issue in 4.1.5 with "Domain Users" not being properly enumerated.&amp;nbsp;&amp;nbsp; However, this problem just re-occurred in 4.1.7 to some extent. The end result is that 90% of my users no longer had Internet access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I ran the command&lt;/P&gt;&lt;P&gt;show user user-IDs | match someuser&lt;/P&gt;&lt;P&gt;I got no results.&amp;nbsp;&amp;nbsp; This problem lasted for over an hour.&amp;nbsp; I have group membership refresh set to 360 seconds.&amp;nbsp; I had to commit the firewall policy multiple times for the group membership to work enumerate correctly.&amp;nbsp; Other groups were enumerating fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to suggest that there is still a bug in this code in 4.1.7.&amp;nbsp;&amp;nbsp; For the time being I have created a new active directory group that isn't special like "domain users" is, and I have added all my domain users to it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Aug 2012 00:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-problem-with-domain-users-enumeration-persists/m-p/6781#M4975</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2012-08-17T00:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: 4.1.7 Problem with Domain Users enumeration persists.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-problem-with-domain-users-enumeration-persists/m-p/6782#M4976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi EdwinD,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have been able to successfully pull members of the 'Domain Users' using 4.1.7. Perhaps the issue is unique to your environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to force a full group membership refresh(as opposed to incremental), the following command can be run:&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id reset group-mapping all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please open a case with support for further investigation if you haven't already done so.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Oct 2012 00:36:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-problem-with-domain-users-enumeration-persists/m-p/6782#M4976</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-10-27T00:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: 4.1.7 Problem with Domain Users enumeration persists.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-problem-with-domain-users-enumeration-persists/m-p/6783#M4977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Support did resolve the issue.&amp;nbsp; Apparently there are multiple ways to setup the domain, and one way works better than the other.&amp;nbsp; Basically, create only one LDAP mapping per domain, and then import all the groups you desire through the single mapping.&amp;nbsp; Do not create a single mapping per LDAP group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Oct 2012 19:51:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/4-1-7-problem-with-domain-users-enumeration-persists/m-p/6783#M4977</guid>
      <dc:creator>EdwinD</dc:creator>
      <dc:date>2012-10-29T19:51:45Z</dc:date>
    </item>
  </channel>
</rss>

