<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PAN-OS 8.1 User-ID problems in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-8-1-user-id-problems/m-p/242710#M69409</link>
    <description>&lt;P&gt;Thank you, with the help of one of the docs you shared I was finally able to solve this. It was the domain-map not woriking well, this doc ( &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK&lt;/A&gt; ) is absolute GOLD!&lt;/P&gt;&lt;P&gt;With some packet captures I was able to troubleshoot a problem related to the retrieval of the partitions from a Domain Controller.&lt;/P&gt;&lt;P&gt;Changed the binding on LDAP of one of the root domain controllers and all started to work !&lt;/P&gt;&lt;P&gt;BTW I already had a group mapping configured on one of the root DCs but i was using the Global Catalog service istead of the normal LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank's!&lt;/P&gt;</description>
    <pubDate>Mon, 10 Dec 2018 13:19:45 GMT</pubDate>
    <dc:creator>LCMember4164</dc:creator>
    <dc:date>2018-12-10T13:19:45Z</dc:date>
    <item>
      <title>PAN-OS 8.1 User-ID problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-8-1-user-id-problems/m-p/242311#M69337</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I have some problems with a user-id installation on PAN-OS 8.1.4, scenario:&lt;/P&gt;&lt;P&gt;1) Windows AD Domain Forest, with around 6/7 domains&lt;/P&gt;&lt;P&gt;2) I'm only interested in authenticating users from one of the domains in the forest&lt;/P&gt;&lt;P&gt;3) I've correctly connected the firewall to the local domain controllers and pulled out ip to user mapping&lt;/P&gt;&lt;P&gt;4) I've also correctly connected the firewall to the ldap servers for group mapping, groups are populated correctly&lt;/P&gt;&lt;P&gt;The domain is in the form: my-local-domain.myforest.local&lt;/P&gt;&lt;P&gt;Problem:&lt;/P&gt;&lt;P&gt;Some users are detected as my-local-domain\username while some others are detected as my-local-domain.myforest.local\username and this gives me some problems because only users in the form my-local-domain\username are correctly mapped to groups.&lt;/P&gt;&lt;P&gt;I've already checked all the new documentation on user-id in 8.1 but cannot make it work &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Looking at one of the users attributes:&lt;BR /&gt;show user user-attributes user my-local-domain\SOMEUSER&lt;BR /&gt;Primary: my-local-domain\SOMEUSER&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Email: SOMEUSER@mydomain.com&lt;BR /&gt;Alt User Names:&lt;BR /&gt;1) SOMEUSER@mydomain.com&lt;BR /&gt;2) my-local-domain\SOMEUSER.USERNAME&lt;BR /&gt;3) my-local-domain\SOMEUSER&lt;BR /&gt;4) SOMEUSER@UPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Basically i would like to configure an Alternate username in the form: my-local-domain.myforest.local\SOMEUSER&lt;/P&gt;&lt;P&gt;is it possible using the new "Alternate Username" feature ? if so... how ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Dec 2018 23:27:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-8-1-user-id-problems/m-p/242311#M69337</guid>
      <dc:creator>LCMember4164</dc:creator>
      <dc:date>2018-12-05T23:27:46Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 8.1 User-ID problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-8-1-user-id-problems/m-p/242376#M69344</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;A had few cases related to similar issue. Most of them was related to:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) wrong Group Mapping Domain Name configuration - check help. If you used this option make sure it is netbios.&lt;/P&gt;&lt;P&gt;b) issue described here:&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Group-Mapping-in-a-Multi-Domain-Active/ta-p/60784" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Group-Mapping-in-a-Multi-Domain-Active/ta-p/60784&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;c) multidomain configuration -&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;d) domain-map was created and not refreshed -&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVDCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVDCA0&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;best&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jarek&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 14:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-8-1-user-id-problems/m-p/242376#M69344</guid>
      <dc:creator>jarbu</dc:creator>
      <dc:date>2018-12-06T14:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-OS 8.1 User-ID problems</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-os-8-1-user-id-problems/m-p/242710#M69409</link>
      <description>&lt;P&gt;Thank you, with the help of one of the docs you shared I was finally able to solve this. It was the domain-map not woriking well, this doc ( &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK&lt;/A&gt; ) is absolute GOLD!&lt;/P&gt;&lt;P&gt;With some packet captures I was able to troubleshoot a problem related to the retrieval of the partitions from a Domain Controller.&lt;/P&gt;&lt;P&gt;Changed the binding on LDAP of one of the root domain controllers and all started to work !&lt;/P&gt;&lt;P&gt;BTW I already had a group mapping configured on one of the root DCs but i was using the Global Catalog service istead of the normal LDAP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank's!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Dec 2018 13:19:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-os-8-1-user-id-problems/m-p/242710#M69409</guid>
      <dc:creator>LCMember4164</dc:creator>
      <dc:date>2018-12-10T13:19:45Z</dc:date>
    </item>
  </channel>
</rss>

