<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem w/ user ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192856#M57887</link>
    <description>&lt;P&gt;Also...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when adding source-user to your policy just type vpn to see if the usergroup self populates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may have already done this but wort a try rather than manually entering the fqdn.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Dec 2017 13:09:47 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2017-12-22T13:09:47Z</dc:date>
    <item>
      <title>Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192839#M57883</link>
      <description>&lt;P&gt;Hi Gurus,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm trying to implement user id agentless.&lt;/P&gt;&lt;P&gt;The LDAP &amp;amp; User Identification are created correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below is the output:&lt;/P&gt;&lt;P&gt;J-C.Valiere.da@PA_Ecore_Master&amp;gt; show user group list&lt;/P&gt;&lt;P&gt;cn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com&lt;BR /&gt;cn=vpn ecore consultant,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J-C.Valiere.da@PA_Ecore_Master&amp;gt; show user user-ids&lt;/P&gt;&lt;P&gt;User Name Vsys Groups&lt;BR /&gt;------------------------------------------------------------------&lt;BR /&gt;corp\tests5 vsys1 cn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com&lt;/P&gt;&lt;P&gt;corp\j-c.valiere.da vsys1 cn=vpn ecore consultant,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, the source zone on which I apply my policy has User-ID enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I can&amp;nbsp;see that tests5 user is member of 'vpn ecore employee'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created the 3 following policy:&lt;/P&gt;&lt;P&gt;"VPN Remote Ecore Employee" {&lt;BR /&gt;to TRUST;&lt;BR /&gt;from REMOTE_VPN_USERS;&lt;BR /&gt;source Pool_VPN_Remote_Users;&lt;BR /&gt;destination VM_Safewalk;&lt;BR /&gt;source-user "cn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com";&lt;BR /&gt;category any;&lt;BR /&gt;application ssl;&lt;BR /&gt;service TCP_8443;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;log-start yes;&lt;BR /&gt;tag REMOTE_VPN_USERS;&lt;BR /&gt;}&lt;BR /&gt;"VPN Remote Ecore Consultant" {&lt;BR /&gt;to TRUST;&lt;BR /&gt;from REMOTE_VPN_USERS;&lt;BR /&gt;source Pool_VPN_Remote_Users;&lt;BR /&gt;destination VM_Safewalk;&lt;BR /&gt;source-user "cn=vpn ecore consultant,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com";&lt;BR /&gt;category any;&lt;BR /&gt;application ssl;&lt;BR /&gt;service TCP_8443;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;log-start yes;&lt;BR /&gt;tag REMOTE_VPN_USERS;&lt;BR /&gt;}&lt;BR /&gt;VPN_Remote_PoolVPN-Safewalk {&lt;BR /&gt;to TRUST;&lt;BR /&gt;from REMOTE_VPN_USERS;&lt;BR /&gt;source Pool_VPN_Remote_Users;&lt;BR /&gt;destination VM_Safewalk;&lt;BR /&gt;source-user any;&lt;BR /&gt;category any;&lt;BR /&gt;application ssl;&lt;BR /&gt;service TCP_8443;&lt;BR /&gt;hip-profiles any;&lt;BR /&gt;action allow;&lt;BR /&gt;log-start yes;&lt;BR /&gt;tag REMOTE_VPN_USERS;&lt;BR /&gt;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And when trying to access the VM_Safewalk on port TCP_8443 with the user tests5, the 3rd policy matches instead of the first one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me what I forgot, or what is wrong in my configuration ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Best Regards,&lt;/P&gt;&lt;P&gt;Jean-Christophe&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 10:28:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192839#M57883</guid>
      <dc:creator>Jean-Christophe</dc:creator>
      <dc:date>2017-12-22T10:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192848#M57885</link>
      <description>&lt;P&gt;If you run the following command...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group name “cn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com”&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is tests5 displayed in the output?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 12:22:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192848#M57885</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-22T12:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192856#M57887</link>
      <description>&lt;P&gt;Also...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when adding source-user to your policy just type vpn to see if the usergroup self populates.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You may have already done this but wort a try rather than manually entering the fqdn.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 13:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192856#M57887</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-22T13:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192857#M57888</link>
      <description>&lt;P&gt;Below is the result:&lt;/P&gt;&lt;P&gt;J-C.Valiere.da@PA_Ecore_Master&amp;gt; show user group name "cn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;short name: corp\vpn ecore employee&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: VPN Ecore Employees&lt;/P&gt;&lt;P&gt;[1 ] corp\j-c.valiere.da&lt;BR /&gt;[2 ] corp\tests5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So looks like everything is fine or ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 13:10:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192857#M57888</guid>
      <dc:creator>Jean-Christophe</dc:creator>
      <dc:date>2017-12-22T13:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192859#M57889</link>
      <description>&lt;P&gt;Try my previous as the policy may need to be...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;corp\vpn ecore employee&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 13:13:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192859#M57889</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-22T13:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192860#M57890</link>
      <description>&lt;P&gt;I can confirm that it is self populated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 13:27:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192860#M57890</guid>
      <dc:creator>Jean-Christophe</dc:creator>
      <dc:date>2017-12-22T13:27:41Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192862#M57892</link>
      <description>&lt;P&gt;Does you authentication include user-domain=corp.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;perhaps a print screen of the successful authentication for tests5 would help.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 13:36:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192862#M57892</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-22T13:36:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192863#M57893</link>
      <description>&lt;P&gt;Sorry... authentication profile&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 13:37:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192863#M57893</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-22T13:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192880#M57897</link>
      <description>&lt;P&gt;Source user in policy applies to "corp\vpn ecore employee"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Jean-Christophe Valiere&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 15:30:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192880#M57897</guid>
      <dc:creator>Jean-Christophe</dc:creator>
      <dc:date>2017-12-22T15:30:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192892#M57899</link>
      <description>&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;I got a really weird thing (Note that I switched tests5 user to vpn ecore consultant):&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J-C.Valiere.da@PA_Ecore_Master&amp;gt; show user group name "cn=vpn ecore consultant,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com"&lt;/P&gt;&lt;P&gt;short name: corp\vpn ecore consultant&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: VPN Ecore Group Mapping&lt;/P&gt;&lt;P&gt;[1 ] corp\tests5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J-C.Valiere.da@PA_Ecore_Master&amp;gt; show user group name "cn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com"&lt;/P&gt;&lt;P&gt;short name: corp\vpn ecore employee&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: VPN Ecore Group Mapping&lt;/P&gt;&lt;P&gt;[1 ] corp\j-c.valiere.da&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;J-C.Valiere.da@PA_Ecore_Master&amp;gt; show user user-ids match-user tests5&lt;/P&gt;&lt;P&gt;User Name Vsys Groups&lt;BR /&gt;------------------------------------------------------------------&lt;BR /&gt;corp\tests5 vsys1 cn=vpn ecore employee,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com&lt;BR /&gt;cn=vpn ecore consultant,ou=roles,ou=global,ou=organization,dc=corp,dc=ecore,dc=com&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So,&lt;/P&gt;&lt;P&gt;Group "vpn ecore employee" contains j-c.valiere.da&lt;/P&gt;&lt;P&gt;Group "vpn ecore consultant" contains tests5&lt;/P&gt;&lt;P&gt;user tests5 belongs to both "vpn ecore employee" and "vpn ecore consultant"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, note that I temporarly disabled the cache in the user identification settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Really, really strange.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 16:11:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192892#M57899</guid>
      <dc:creator>Jean-Christophe</dc:creator>
      <dc:date>2017-12-22T16:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Problem w/ user ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192901#M57901</link>
      <description>&lt;P&gt;Wow that is strange, maybe remembered from previous session.&lt;/P&gt;&lt;P&gt;could you post a screen shot of monitor/system for the users authentication success. For tests5.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2017 16:39:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-w-user-id/m-p/192901#M57901</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-22T16:39:37Z</dc:date>
    </item>
  </channel>
</rss>

