<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 8.1.0 Upgrade issue: Group names in allow-list of an LDAP authentication profile no longer work in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204341#M60123</link>
    <description>&lt;P&gt;Also, this may not be specific to an 8.1.0 upgrade, that's just the event that caused me to experience it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other thing with the upgrade is it can clear out the %USERINPUT% and set it to "None" on the Auth Profile's UserName Modifier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Mar 2018 15:48:20 GMT</pubDate>
    <dc:creator>bspilde</dc:creator>
    <dc:date>2018-03-08T15:48:20Z</dc:date>
    <item>
      <title>8.1.0 Upgrade issue: Group names in allow-list of an LDAP authentication profile no longer work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204241#M60101</link>
      <description>&lt;P&gt;Group “Allow lists” no longer worked for LDAP authentications. We could no longer connect to GlobalProtect until set it to All or specified each LDAP user account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We had to forcefully clear the ID Manager database&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; debug user-id reset user-id-manager type user-group&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 23:22:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204241#M60101</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2018-03-07T23:22:33Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.0 Upgrade issue: Group names in allow-list of an LDAP authentication profile no longer work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204256#M60104</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/71"&gt;@bspilde&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I don't believe that this is actually a reported issue as of yet; at least not that I saw with a quick look through the release notes. Out of curiosity did you actually report this to TAC, and did reseting the ID Manager database actually resolve the issue and allow you to utilize the allow lists?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 02:19:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204256#M60104</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-03-08T02:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.0 Upgrade issue: Group names in allow-list of an LDAP authentication profile no longer work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204340#M60122</link>
      <description>&lt;P&gt;Yes this resolution was via TAC and all is well now after resetting the database.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 15:43:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204340#M60122</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2018-03-08T15:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.0 Upgrade issue: Group names in allow-list of an LDAP authentication profile no longer work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204341#M60123</link>
      <description>&lt;P&gt;Also, this may not be specific to an 8.1.0 upgrade, that's just the event that caused me to experience it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The other thing with the upgrade is it can clear out the %USERINPUT% and set it to "None" on the Auth Profile's UserName Modifier.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 15:48:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/204341#M60123</guid>
      <dc:creator>bspilde</dc:creator>
      <dc:date>2018-03-08T15:48:20Z</dc:date>
    </item>
    <item>
      <title>Re: 8.1.0 Upgrade issue: Group names in allow-list of an LDAP authentication profile no longer work</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/258125#M73225</link>
      <description>&lt;P&gt;I had the same issue after upgrade to 8.1. As I had not seen this article I have not yet tried clearing the groupID db.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I decided to downgrade instead to further research. I&amp;nbsp; found that even with a pre upgrade backup that was used during the downgrade, the issue persists.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I discovered that deleteing the auth profile and then re-syncing from the untocuhed HA partner returned it to expected function.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Apr 2019 19:02:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/8-1-0-upgrade-issue-group-names-in-allow-list-of-an-ldap/m-p/258125#M73225</guid>
      <dc:creator>NeilR</dc:creator>
      <dc:date>2019-04-19T19:02:28Z</dc:date>
    </item>
  </channel>
</rss>

