<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP interval in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-interval/m-p/222119#M63890</link>
    <description>&lt;P&gt;Yes thats where it is.... the default if left blank is 3600 seconds, &amp;nbsp;1 hour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i suppose it depends on how many users and groups are incorporated between PA and AD.&lt;/P&gt;&lt;P&gt;with almost 10k userbase and making good use of the domain users group as well as many other large groups i left it at the default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i run the same refresh command in an emergency but rarely use it as AD user movementhere &amp;nbsp;involves several emails and 12 meetings... by the time the user is notified a week has passed.... &amp;nbsp;you could use api to make the refresh a lot smoother...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... i would say really depends on your userbase, group activity and urgency.&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jul 2018 04:39:39 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-07-13T04:39:39Z</dc:date>
    <item>
      <title>LDAP interval</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-interval/m-p/222026#M63880</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a question in reference to the LDAP interval time. Specifically what my goal is I want to be able to let the firewall know about my AD group membership changes quicker. For example if I have a specific AD group that is configured on the fw to control a specific PBF rule, when I add or remove a domain account from that AD group, what is the default refresh time (same as interval time?) that I need to wait for the fw to scan the AD group to get the update?&lt;/P&gt;&lt;P&gt;I usually run two commands to make the change immediate:&lt;/P&gt;&lt;P&gt;a.&amp;nbsp;debug user-id refresh group-mapping all&lt;/P&gt;&lt;P&gt;b.&amp;nbsp;debug user-id reset group-mapping all&lt;/P&gt;&lt;P&gt;I do understand that decreasing the refresh time (interval time? LOL!) might cause bugging down the CPU on the fw and it might cause more network bandwidth utilization but I just wanted to undersatnd:&lt;/P&gt;&lt;P&gt;1. where can I change the refresh time? Is that located in:&lt;/P&gt;&lt;P&gt;Device -&amp;gt; User Identification -&amp;gt; Group Mapping Settigns -&amp;gt; Server Porofie tab ("Update Interval" field)?&lt;/P&gt;&lt;P&gt;2. If I am incorrect in assuming that the Update Interval time field (above) is responsible for AD updates, what is the correct setting and where can I change it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 21:52:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-interval/m-p/222026#M63880</guid>
      <dc:creator>NetOverLord</dc:creator>
      <dc:date>2018-07-12T21:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP interval</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-interval/m-p/222119#M63890</link>
      <description>&lt;P&gt;Yes thats where it is.... the default if left blank is 3600 seconds, &amp;nbsp;1 hour.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i suppose it depends on how many users and groups are incorporated between PA and AD.&lt;/P&gt;&lt;P&gt;with almost 10k userbase and making good use of the domain users group as well as many other large groups i left it at the default.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i run the same refresh command in an emergency but rarely use it as AD user movementhere &amp;nbsp;involves several emails and 12 meetings... by the time the user is notified a week has passed.... &amp;nbsp;you could use api to make the refresh a lot smoother...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... i would say really depends on your userbase, group activity and urgency.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jul 2018 04:39:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-interval/m-p/222119#M63890</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-13T04:39:39Z</dc:date>
    </item>
  </channel>
</rss>

