<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Palo Alto Mapping problem adding new groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-mapping-problem-adding-new-groups/m-p/150823#M50026</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a PA3050 and we are expecting a problem related to Group mapping. We have added two new groups in LDAP Group mapping profile. We can add these 2 groups using WebUIS "Included groups", we launch a refresh userid group-mapping but when we run "show user group-mapping state all", we can see all goups but not the new ones added.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why Pa is not detecting the new groups added. We see this error in system logs "PA fetch group LDAP" but PA can connect to LDAP properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its version 7.0.11, any bug related to this?&lt;/P&gt;</description>
    <pubDate>Mon, 03 Apr 2017 11:17:56 GMT</pubDate>
    <dc:creator>Es_tecsupportsecurity</dc:creator>
    <dc:date>2017-04-03T11:17:56Z</dc:date>
    <item>
      <title>Palo Alto Mapping problem adding new groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-mapping-problem-adding-new-groups/m-p/150823#M50026</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a PA3050 and we are expecting a problem related to Group mapping. We have added two new groups in LDAP Group mapping profile. We can add these 2 groups using WebUIS "Included groups", we launch a refresh userid group-mapping but when we run "show user group-mapping state all", we can see all goups but not the new ones added.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why Pa is not detecting the new groups added. We see this error in system logs "PA fetch group LDAP" but PA can connect to LDAP properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its version 7.0.11, any bug related to this?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 11:17:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-mapping-problem-adding-new-groups/m-p/150823#M50026</guid>
      <dc:creator>Es_tecsupportsecurity</dc:creator>
      <dc:date>2017-04-03T11:17:56Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto Mapping problem adding new groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-mapping-problem-adding-new-groups/m-p/150901#M50042</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not necessarily a bug; could be something in the configuration or whatnot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do one thing, take a pcap on the MGMT interface (unless some other interface is being used for LDAP).&lt;/P&gt;&lt;P&gt;1) Open a CLI session to the firewall&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@anuragFW&amp;gt;&amp;nbsp;&lt;/SPAN&gt;tcpdump&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Open another CLI session to the firewall&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;admin@anuragFW&amp;gt;&lt;/SPAN&gt;&amp;nbsp;debug user-id refresh group-mapping all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) verify that the last action time shows a fresh time count:&lt;/P&gt;&lt;P&gt;admin@anuragFW&amp;gt; show user group-mapping state ourgroups&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Group Mapping((null), type: active-directory): ourgroups&lt;BR /&gt;Bind DN : anurag@xxxx.xxx&lt;BR /&gt;Base : DC=xxxxx,DC=xxx&lt;BR /&gt;Group Filter: (None)&lt;BR /&gt;User Filter: (None)&lt;BR /&gt;Servers : configured 1 servers&lt;BR /&gt;10.21.56.14(389)&lt;BR /&gt;&lt;STRONG&gt;Last Action Time: 1 secs ago(took 0 secs)&lt;/STRONG&gt;&lt;BR /&gt;Next Action Time: In 3599 secs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) Stop the tcpdump by pressing Ctrl+C&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;5) Transfer the pcap for easy viewing:&lt;/P&gt;&lt;P&gt;admin@anuragFW&amp;gt; tftp export mgmt-pcap from mgmt.pcap to x.x.x.x&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, filter for the LDAP server and check what we are receiving from the LDAP server that's causing the error in the system logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2017 18:55:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-mapping-problem-adding-new-groups/m-p/150901#M50042</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-04-03T18:55:14Z</dc:date>
    </item>
  </channel>
</rss>

