<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication via LDAP server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238906#M68430</link>
    <description>&lt;P&gt;just bear in mind overheads,,, with some 15k userbase we probably wont be reducing it...&lt;/P&gt;</description>
    <pubDate>Wed, 07 Nov 2018 16:34:29 GMT</pubDate>
    <dc:creator>Mick_Ball</dc:creator>
    <dc:date>2018-11-07T16:34:29Z</dc:date>
    <item>
      <title>Authentication via LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238896#M68426</link>
      <description>&lt;P&gt;We have a PA-3050, I have setup LDAP auth and it is working fine, however I have a question/concern.&amp;nbsp; Yesterday we had a user offsite who needed VPN access, he was not in the AD group initially, so I added him to the AD group and sent him instructions on how to download the agent, when he tried to sign in, it would not allow him, ten or so mins passed and it finally authenticated him and he was able to download the agent and get on VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there some sort of sync time I can change?&amp;nbsp; My understanding is that it checks local users then passes off to the LDAP profile, so why would it take ten mins?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 16:20:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238896#M68426</guid>
      <dc:creator>TommyScott</dc:creator>
      <dc:date>2018-11-07T16:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238903#M68427</link>
      <description>&lt;P&gt;group membership is not dynamic, the palo checks ever 20 mins or so...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can force the update of group membership with the following command...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;debug user-id refresh group mapping all&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or replace "all" with the group name to update just one group (CN= etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 16:26:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238903#M68427</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-07T16:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238904#M68428</link>
      <description>&lt;P&gt;Is there anyway to change that?&amp;nbsp; Sometimes last minute things happen and sure we can force it but ideally taking the refresh down to around 2mins or so would work way better.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 16:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238904#M68428</guid>
      <dc:creator>TommyScott</dc:creator>
      <dc:date>2018-11-07T16:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238905#M68429</link>
      <description>&lt;P&gt;Sure..&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;device\user identification\group mapping settings.&lt;/P&gt;&lt;P&gt;open your group mapping and modify update interval on top right hand corner...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;default is actually 3600 seconds (1 hour)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure why i calculated that for you...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 16:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238905#M68429</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-07T16:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238906#M68430</link>
      <description>&lt;P&gt;just bear in mind overheads,,, with some 15k userbase we probably wont be reducing it...&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 16:34:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238906#M68430</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-07T16:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238923#M68439</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="usermap.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/17459i765AB109D26D8885/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="usermap.png" alt="usermap.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 17:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238923#M68439</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-11-07T17:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication via LDAP server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238928#M68442</link>
      <description>&lt;P&gt;Yeah, I saw it right after I hit submit, thanks for following up.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Nov 2018 17:39:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-via-ldap-server/m-p/238928#M68442</guid>
      <dc:creator>TommyScott</dc:creator>
      <dc:date>2018-11-07T17:39:04Z</dc:date>
    </item>
  </channel>
</rss>

