<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UIA 8.1 issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/uia-8-1-issue/m-p/231941#M66589</link>
    <description>&lt;P&gt;I have two different customers who hits same issue.&lt;/P&gt;&lt;P&gt;One user is using PAN-OS 8.1.3 and UIA 8.1.3-10,&lt;/P&gt;&lt;P&gt;another is using PAN-OS 8.0.12 and UIA 8.1.3.-10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is that UIA detects user info as three types of formats like...&lt;/P&gt;&lt;P&gt;1) domain\user (this is same as previous version)&lt;/P&gt;&lt;P&gt;2) domain.local\user&lt;/P&gt;&lt;P&gt;3) user@domain.local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When PA received these info, "show user ip-user-mapping all" shows following two types as below&lt;/P&gt;&lt;P&gt;1) domain\user&lt;/P&gt;&lt;P&gt;2) domain.local\user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@hostname(active)&amp;gt; show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;BR /&gt;--------------- ------ ------- -------------------------------- -------------- -------------&lt;BR /&gt;10.241.73.100 vsys1 UIA domain\user1 Never Never&lt;BR /&gt;10.212.136.101 vsys1 UIA domain.local\user1 Never Never&lt;BR /&gt;10.224.57.100 vsys1 UIA domain\user1 Never Never&lt;BR /&gt;10.128.145.9 vsys1 UIA domain\user2 Never Never&lt;BR /&gt;10.128.144.35 vsys1 UIA domain.local\user3 Never Never&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is that when PA recognize user format as "domain.local\user" format, the user does not hit to policy which was configured by user group that was pulled from AD.&lt;/P&gt;&lt;P&gt;The reason is that user group and member was recognized ONLY by "domain\user' format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@hostname(active)&amp;gt; show user group name "cn=domain users,cn=users,dc=domain,dc=local&lt;/P&gt;&lt;P&gt;short name: domain\domain users&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: groupmapping&lt;/P&gt;&lt;P&gt;[1 ] domain\01&lt;BR /&gt;[2 ] domain\21&lt;BR /&gt;[3 ] domain\22&lt;BR /&gt;[4 ] domain\23&lt;BR /&gt;[5 ] domain\24&lt;BR /&gt;[6 ] domain\26&lt;BR /&gt;[7 ] domain\27&lt;BR /&gt;[8 ] domain\29&lt;BR /&gt;[9 ] domain\88&lt;BR /&gt;[10 ] domain\98&lt;BR /&gt;[11 ] domain\administrator&lt;BR /&gt;[12 ] domain\agroadmin&lt;BR /&gt;[13 ] domain\agrotest&lt;BR /&gt;[14 ] domain\alc&lt;BR /&gt;[15 ] domain\amano1&lt;BR /&gt;[16 ] domain\amano2&lt;BR /&gt;..so on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe on PAN-OS 8.0 and earlier, "domain\userA" and "domain.local\userA" is NOT same guy, thus it does not hit group members.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any body who hits same issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: I know PAN-OS 8.1 starts supporting multiple formats, though it makes me confusing and hitting this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;</description>
    <pubDate>Sun, 23 Sep 2018 09:31:58 GMT</pubDate>
    <dc:creator>emr_1</dc:creator>
    <dc:date>2018-09-23T09:31:58Z</dc:date>
    <item>
      <title>UIA 8.1 issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uia-8-1-issue/m-p/231941#M66589</link>
      <description>&lt;P&gt;I have two different customers who hits same issue.&lt;/P&gt;&lt;P&gt;One user is using PAN-OS 8.1.3 and UIA 8.1.3-10,&lt;/P&gt;&lt;P&gt;another is using PAN-OS 8.0.12 and UIA 8.1.3.-10.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is that UIA detects user info as three types of formats like...&lt;/P&gt;&lt;P&gt;1) domain\user (this is same as previous version)&lt;/P&gt;&lt;P&gt;2) domain.local\user&lt;/P&gt;&lt;P&gt;3) user@domain.local&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When PA received these info, "show user ip-user-mapping all" shows following two types as below&lt;/P&gt;&lt;P&gt;1) domain\user&lt;/P&gt;&lt;P&gt;2) domain.local\user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@hostname(active)&amp;gt; show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;IP Vsys From User IdleTimeout(s) MaxTimeout(s)&lt;BR /&gt;--------------- ------ ------- -------------------------------- -------------- -------------&lt;BR /&gt;10.241.73.100 vsys1 UIA domain\user1 Never Never&lt;BR /&gt;10.212.136.101 vsys1 UIA domain.local\user1 Never Never&lt;BR /&gt;10.224.57.100 vsys1 UIA domain\user1 Never Never&lt;BR /&gt;10.128.145.9 vsys1 UIA domain\user2 Never Never&lt;BR /&gt;10.128.144.35 vsys1 UIA domain.local\user3 Never Never&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue is that when PA recognize user format as "domain.local\user" format, the user does not hit to policy which was configured by user group that was pulled from AD.&lt;/P&gt;&lt;P&gt;The reason is that user group and member was recognized ONLY by "domain\user' format.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;admin@hostname(active)&amp;gt; show user group name "cn=domain users,cn=users,dc=domain,dc=local&lt;/P&gt;&lt;P&gt;short name: domain\domain users&lt;/P&gt;&lt;P&gt;source type: ldap&lt;BR /&gt;source: groupmapping&lt;/P&gt;&lt;P&gt;[1 ] domain\01&lt;BR /&gt;[2 ] domain\21&lt;BR /&gt;[3 ] domain\22&lt;BR /&gt;[4 ] domain\23&lt;BR /&gt;[5 ] domain\24&lt;BR /&gt;[6 ] domain\26&lt;BR /&gt;[7 ] domain\27&lt;BR /&gt;[8 ] domain\29&lt;BR /&gt;[9 ] domain\88&lt;BR /&gt;[10 ] domain\98&lt;BR /&gt;[11 ] domain\administrator&lt;BR /&gt;[12 ] domain\agroadmin&lt;BR /&gt;[13 ] domain\agrotest&lt;BR /&gt;[14 ] domain\alc&lt;BR /&gt;[15 ] domain\amano1&lt;BR /&gt;[16 ] domain\amano2&lt;BR /&gt;..so on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe on PAN-OS 8.0 and earlier, "domain\userA" and "domain.local\userA" is NOT same guy, thus it does not hit group members.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any body who hits same issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: I know PAN-OS 8.1 starts supporting multiple formats, though it makes me confusing and hitting this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Emr&lt;/P&gt;</description>
      <pubDate>Sun, 23 Sep 2018 09:31:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uia-8-1-issue/m-p/231941#M66589</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2018-09-23T09:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: UIA 8.1 issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/uia-8-1-issue/m-p/235684#M67556</link>
      <description>&lt;P&gt;Reply to myself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was&amp;nbsp;&lt;SPAN&gt;WINAGENT-391 issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Description:&lt;BR /&gt;&lt;SPAN&gt;Fixed an issue where the User-ID agent failed to normalize usernames correctly due to a domain map lookup failure.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This is fixed in UIA 8.1.4.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 00:24:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/uia-8-1-issue/m-p/235684#M67556</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2018-10-17T00:24:37Z</dc:date>
    </item>
  </channel>
</rss>

