<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GlobalProtect not using AD group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176118#M55099</link>
    <description>&lt;P&gt;firstly, check the monitor\system log to ensure you are authenticating as domain\user name&amp;nbsp;to both the portal and gateway.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Sep 2017 13:38:24 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-09-12T13:38:24Z</dc:date>
    <item>
      <title>GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176108#M55098</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running a PA-VM&amp;nbsp;on AWS. It has two interfaces, one for management, one for data.&lt;/P&gt;&lt;P&gt;I have created an LDAP&amp;nbsp;connection to our network and can log into GP using my AD credentials. So far, so good.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to have separation of users and assigned IPs based on group membership. I have an authentication profile with two sequences. One to match on the group that my account is a member of, the second uses local authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the GP gateway, I have the authentication set to the auth&amp;nbsp;sequence (which uses the first authentication profile - the one that should match my account and group set first), and in the agent client settings, I have two entries. the first one should give me an IP address from the first range, the second entry is set to any/any and gives an IP from a different range.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I connect, I use my username/password from AD but get an IP address from the second range.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The logs show these entries (note I have replaced the actual AD details):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1,2017/09/12 05:48:17,4E0FEDAE31E65C2,31,0x0,USERID,login,53,2017/09/12 05:48:17,0,0,0,0,,PA-VM,1,vsys1,10.7.2.10,xx\sfordham,,0,1,2592000,0,0,vpn-client,globalprotect,0,0,,2017/09/12 05:48:18,1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt; show user group-mapping state all&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Group Mapping(vsys1, type: active-directory): SaaS-Users&lt;BR /&gt;Bind DN : CN=xxx,OU=xxx xxx - Shared,DC=XX,DC=xxx&lt;BR /&gt;Base : DC=XX,DC=xxx&lt;BR /&gt;Group Filter: (None)&lt;BR /&gt;User Filter: (None)&lt;BR /&gt;Servers : configured 1 servers&lt;BR /&gt;213.78.96.130(389)&lt;BR /&gt;Last Action Time: 1607 secs ago(took 0 secs)&lt;BR /&gt;Next Action Time: In 1993 secs&lt;BR /&gt;Number of Groups: 1&lt;BR /&gt;cn=replaced_xxx,ou=security groups with mailbox,ou=security groups - shared,dc=xx,dc=xxx&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt; show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;BR /&gt;--------------- ------ ------- -------------------------------- -------------- -------------&lt;BR /&gt;10.7.2.10 vsys1 GP xx\sfordham 2591689 2591689&lt;BR /&gt;Total: 1 users&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From what I have read, GP in the above command *should* be AD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@PA-VM&amp;gt; show user user-ids&lt;/P&gt;&lt;P&gt;User Name Vsys Groups&lt;BR /&gt;------------------------------------------------------------------&lt;BR /&gt;xx.xxx\sfordham vsys1 cn=replaced_xxx,ou=security groups with mailbox,ou=security groups - shared,dc=xx,dc=xxx&lt;BR /&gt;Total: 22&lt;BR /&gt;admin@PA-VM&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So it looks like it is reading all of the necessary details - I can log in using my AD account, for example - it's just the mapping that's incorrect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone advise?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies if I have missed something blindingly obvious. I only started working&amp;nbsp;with PA last week, so am learning as I go!&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 12:58:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176108#M55098</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T12:58:15Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176118#M55099</link>
      <description>&lt;P&gt;firstly, check the monitor\system log to ensure you are authenticating as domain\user name&amp;nbsp;to both the portal and gateway.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 13:38:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176118#M55099</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T13:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176119#M55100</link>
      <description>&lt;P&gt;sorry, cancel the above....&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 13:40:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176119#M55100</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T13:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176121#M55101</link>
      <description>&lt;P&gt;Ok, cancelling... but here are the logs just in case...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-authentication.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11227i8A8670B2C35BC971/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-authentication.PNG" alt="PA-authentication.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 13:43:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176121#M55101</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T13:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176122#M55102</link>
      <description>&lt;P&gt;could you confirm that under network/gateways/(gateway name)/agent&amp;nbsp;&amp;nbsp;&amp;nbsp; that you have 2 configs.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 13:57:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176122#M55102</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T13:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176123#M55103</link>
      <description>&lt;P&gt;oops.. missed off /client settings&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 13:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176123#M55103</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T13:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176125#M55104</link>
      <description>&lt;P&gt;Check! both are there, and I am getting an IP address from the Corp pool - not the first pool as I would like...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-agents.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11228iEDBF9B4C34584BA3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-agents.PNG" alt="PA-agents.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:01:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176125#M55104</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T14:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176126#M55105</link>
      <description>&lt;P&gt;open up your first config and add another user, start typing sford and see if your name auto appears&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:09:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176126#M55105</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T14:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176129#M55107</link>
      <description>&lt;P&gt;That works:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-agents2.PNG" style="width: 391px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11229iA09E17BDC461CCDF/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-agents2.PNG" alt="PA-agents2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176129#M55107</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T14:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176130#M55108</link>
      <description>&lt;P&gt;could you provide print screen of ldap auth profile&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:17:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176130#M55108</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T14:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176135#M55109</link>
      <description>&lt;P&gt;I this what you mean?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-ldap-auth1.PNG" style="width: 603px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11231i1E86A052E536EB44/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-ldap-auth1.PNG" alt="PA-ldap-auth1.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-ldap-auth2.PNG" style="width: 601px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11230i0596C84B1EF557DD/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-ldap-auth2.PNG" alt="PA-ldap-auth2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are no settings under "Factors"&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176135#M55109</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T14:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176136#M55110</link>
      <description>&lt;P&gt;ok i'm not so good with domain names, we do not have a something.local in our domain name. just a single entry.&lt;/P&gt;&lt;P&gt;hopefully someone else will jump in with more domain experience but could you just post device/user id/group mapping settings/(name)/server profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also.. under the gateway client settings, just enter your name manually without domain info. and test.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:30:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176136#M55110</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T14:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176140#M55111</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-Group-mapping2.PNG" style="width: 630px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11232i6B64F379D5771743/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-Group-mapping2.PNG" alt="PA-Group-mapping2.PNG" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-Group-mapping.PNG" style="width: 626px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11233i195D178E7F76A5FB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-Group-mapping.PNG" alt="PA-Group-mapping.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only difference I can see is that the domain is uppercase here - but I can drill into it and select the group, so I think this is probably not causing an issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I added myself as a new entry as you suggested:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PA-three-clients.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/11234i10999F7A9F6B5790/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="PA-three-clients.PNG" alt="PA-three-clients.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I still get an IP address from the 10.7.2. range.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:41:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176140#M55111</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T14:41:08Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176142#M55112</link>
      <description>&lt;P&gt;you have added yourself with domain info.&amp;nbsp; dont select yourself from the list, just type it in and ignore name in list. just click whitespace and it will stick.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176142#M55112</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T14:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176143#M55113</link>
      <description>&lt;P&gt;Tried that, it just shows sfordham, but I still jump down to the Corp entry.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:58:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176143#M55113</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T14:58:51Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176144#M55114</link>
      <description>&lt;P&gt;OK I is miffed, all the above works for me, i may be ciutching at straws but it could be worth changing your corp pool to a different subnet, I know user IP's are cached per user but not sure if this applies to different agent configs.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 15:05:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176144#M55114</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T15:05:12Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176149#M55115</link>
      <description>&lt;P&gt;Me too Mick!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I created a new AD group - first checking that spaces in OUs are OK (&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Usernames-Not-Retrieved-by-the-Firewall-with-OU-for-LDAP-Server/ta-p/59174" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Usernames-Not-Retrieved-by-the-Firewall-with-OU-for-LDAP-Server/ta-p/59174&lt;/A&gt;) and added my user to that - also the other group was a distribution group, new group is a security group (just in case).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edited the config to use the new group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changed the pool for Corp to 10.7.3.10-10.7.3.200.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Reconnected to the VPN - now getting a 10.7.3.10 address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ever feel like you are going round in circles? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 15:36:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176149#M55115</guid>
      <dc:creator>StuartFordham</dc:creator>
      <dc:date>2017-09-12T15:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176151#M55116</link>
      <description>&lt;P&gt;i dont think this is an issue with OU's as your name was retrieved when you started to type it in.&lt;/P&gt;&lt;P&gt;lets not give up hope as there are some clever peeps out there that have bailed me out on many occasions, and it's still quite a fresh call.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;here are a number of things i would try, just for diags.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1, in your ldap profile and in your group id settings. just change the domain field to "test", commit, and then&amp;nbsp;remove your name from the gateway config and add it again.&amp;nbsp;&amp;nbsp;it should auto populate under the domain "test" regardless of the real domain name.&lt;/P&gt;&lt;P&gt;try to connect again...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2, with the above still in place, clone your portal agent config, move it to the top and add your name here also.&lt;/P&gt;&lt;P&gt;i like to do this in the portal as the monitor/system tab shows you what portal config is being used, it does not seem to show this in the logs for gateway configs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;by the time you have done this, someone will jump in and make us both look stupid....&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 15:57:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176151#M55116</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T15:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176152#M55117</link>
      <description>&lt;P&gt;also, are you on V8.x&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 15:59:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176152#M55117</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T15:59:09Z</dc:date>
    </item>
    <item>
      <title>Re: GlobalProtect not using AD group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176157#M55119</link>
      <description>&lt;P&gt;hmm... forget option 1. tried again and didn't work second time....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps just change the domain name to&amp;nbsp; the bit that you hace squiggled out. omitting .local.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2017 17:09:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/globalprotect-not-using-ad-group/m-p/176157#M55119</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-12T17:09:09Z</dc:date>
    </item>
  </channel>
</rss>

