<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP groups not populating correctly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218648#M63195</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13668"&gt;@Nathan.S&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So you really had to add a single user to the group mapping? ... sounds like a bug to me ...&lt;/P&gt;&lt;P&gt;You could try to update to 8.1.2 ... maybe your lucky and then it "magically" works.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jun 2018 21:41:22 GMT</pubDate>
    <dc:creator>Remo</dc:creator>
    <dc:date>2018-06-20T21:41:22Z</dc:date>
    <item>
      <title>LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218276#M63102</link>
      <description>&lt;P&gt;PA220, PANOS 8.1.1&lt;BR /&gt;&lt;BR /&gt;Working on setting up GlobalProtect using AD/LDAP auth and groups to define access.&amp;nbsp;&lt;BR /&gt;I have userconfigs setup by AD Group and the log is "matching config not found"&amp;nbsp;&lt;BR /&gt;On digging into it some more, it appears that the user, in the PA, doesn't have the appropriate groups attached. Despite that they do in AD.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;AD Group has four members. Three of the members show up in the PA. The fourth does not.&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;show user user-ids match-user domain\ProblemUser&lt;/EM&gt;&amp;nbsp; returns an empty table. While the other three users in the group return complete information as expected.&amp;nbsp;&lt;BR /&gt;Account is functional and has full access to what all it's supposed to from the AD side of things.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I've done a&amp;nbsp;&lt;EM&gt;debug user-id reset group-mapping all&lt;/EM&gt; and I'm&amp;nbsp; still having the same issues.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Where should I start troubleshooting from here?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:12:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218276#M63102</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-18T20:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218283#M63103</link>
      <description>&lt;P&gt;Is the problematic user in the same OU as the other three? Or more specific: is the user in an OU that is covered by the base DN that you specified in the LDAP server profile?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:32:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218283#M63103</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-18T20:32:12Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218284#M63104</link>
      <description>&lt;P&gt;All four users are in the same OU and are covered by the Base DN.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:33:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218284#M63104</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-18T20:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218286#M63105</link>
      <description>&lt;P&gt;When you do the opposite as you already did with the command "show user group name GROUPNAME", there the problem user is also missing right?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:39:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218286#M63105</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-18T20:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218287#M63106</link>
      <description>&lt;P&gt;Correct, ProblemUser does not show up as a member of the group in the PA.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:43:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218287#M63106</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-18T20:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218291#M63110</link>
      <description>&lt;P&gt;Is - for whatever reason - the user in an exclude list or excluded in the LDAP filter in the Group mapping settings?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:56:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218291#M63110</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-18T20:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218292#M63111</link>
      <description>&lt;P&gt;Nope, I don't have anything in the excludes.&lt;BR /&gt;Group Mapping is only looking at the AD Group.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:58:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218292#M63111</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-18T20:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218368#M63129</link>
      <description>&lt;P&gt;i assume you are using different AD accounts for user administration and ldap, it may be worth setting up another ldap profile with the full admin account and re test “show user group name..” . just to ensure the user is not masked somehow within AD.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 15:59:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218368#M63129</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-06-19T15:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218370#M63130</link>
      <description>&lt;P&gt;The account in question isn't setup for admin rights to the PA, only auth for the GP&amp;nbsp;portal.&amp;nbsp;&lt;BR /&gt;The LDAP Admins group is working correctly and shows up in the "show user group name" as expected.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I'm using a single LDAP Server Profile setup in the PA.&amp;nbsp;&lt;BR /&gt;GroupMapping then is looking for specific groups. and then GP is limited further by group membership.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Did I follow you correctly?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218370#M63130</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-19T16:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218371#M63131</link>
      <description>&lt;P&gt;I dont think you understood me.. sorry....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nothing to do with pa admins...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your ldap profile has a bind account and password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when you administer your domain i assume you are using a different account to the bind one...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;try that AD admin account as your ldap bind.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:15:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218371#M63131</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-06-19T16:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218373#M63132</link>
      <description>&lt;P&gt;Okay, I follow you now.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I just switched to my domain admin and now the group membership shows correctly.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Now I'll go talk to the AD admin and find out what needs to happen to make this work.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for your input!&lt;BR /&gt;I'll update if/when I find the cure.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218373#M63132</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-19T16:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218375#M63133</link>
      <description>&lt;P&gt;Nice one, sorry for the confusion....&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jun 2018 16:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218375#M63133</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-06-19T16:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218637#M63190</link>
      <description>&lt;P&gt;Update.&amp;nbsp;&lt;BR /&gt;After banging our head on it a lot lately, we finally found that adding the Domain Users group to the GroupMapping resolved the issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Unclear why this is the case, but maybe it'll help someone else in the future.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;edited to improve clarity&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 18:42:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218637#M63190</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-21T18:42:55Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218648#M63195</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/13668"&gt;@Nathan.S&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So you really had to add a single user to the group mapping? ... sounds like a bug to me ...&lt;/P&gt;&lt;P&gt;You could try to update to 8.1.2 ... maybe your lucky and then it "magically" works.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 21:41:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218648#M63195</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-06-20T21:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218760#M63222</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/16592"&gt;@Remo&lt;/a&gt;&amp;nbsp;No, I had to add the group Domain Users to the Group Mapping to get the details on the users to show correctly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 18:42:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218760#M63222</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-21T18:42:17Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218872#M63238</link>
      <description>&lt;P&gt;so... to confirm...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;your portal agent config is set to a certain group, but the full group only works if you add "domain users" to the group mapping "group include" list.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you have just added the users individually in the portal agent config and this only works when you add "domain users" to the group mapping "group include" list..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or none of the above....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 13:57:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218872#M63238</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-06-22T13:57:01Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218886#M63241</link>
      <description>&lt;P&gt;Portal config is set by AD Group.&amp;nbsp;&lt;BR /&gt;When I only put the usergroups I'm selecting into the Auth Profile, it only works for some users.&amp;nbsp;&lt;BR /&gt;When I put the usergroups I want for GP Auth AND add the group "Domain Users" to the Auth Profile, then all the users work.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 14:20:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218886#M63241</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-22T14:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218887#M63242</link>
      <description>&lt;P&gt;so in effect... your are granting GP access to all users, or have i missed something here...&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 14:24:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218887#M63242</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-06-22T14:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218888#M63243</link>
      <description>&lt;P&gt;cancel that, let me read that again....&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 14:25:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218888#M63243</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-06-22T14:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP groups not populating correctly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218889#M63244</link>
      <description>&lt;P&gt;Sorta, but not really.&amp;nbsp;&lt;BR /&gt;All users will get authenticated, but won't be allowed access because they won't have a matching config in GP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jun 2018 14:26:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-groups-not-populating-correctly/m-p/218889#M63244</guid>
      <dc:creator>Nathan.S</dc:creator>
      <dc:date>2018-06-22T14:26:14Z</dc:date>
    </item>
  </channel>
</rss>

