<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policy not working with Group Mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/249003#M70838</link>
    <description>&lt;P&gt;For userid we are using user id agent running on windows.&lt;/P&gt;&lt;P&gt;So PA talk to those user id agents and get the mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for group mapping we use ldap also we use domain name with it&lt;/P&gt;&lt;P&gt;I have already run those commands and not much i can find in them&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;idle timeout for user id agent is 4 hours.&lt;/P&gt;&lt;P&gt;In group mappings i see update interval to default ?&lt;/P&gt;&lt;P&gt;should i increase the value here to like 4 hours?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Feb 2019 12:59:29 GMT</pubDate>
    <dc:creator>MP18</dc:creator>
    <dc:date>2019-02-06T12:59:29Z</dc:date>
    <item>
      <title>Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248962#M70821</link>
      <description>&lt;P&gt;I have configured LDAP group under Group Map settings.&lt;/P&gt;&lt;P&gt;I have added the ldap group there.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then under security policy source user is any and under user i added that group name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i do sh user group list i see the group name and user ids under it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i try to reach the destination ip under that rule firewall denies that traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zone1 and destination is zone 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have enabled used id under zone 1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i see deny in firewall i see my user id there&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 04:30:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248962#M70821</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T04:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248972#M70822</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;BR /&gt;&lt;P&gt;Traffic flow in firewall&amp;nbsp; -&amp;nbsp; zone1 then zone 2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic has to come via Zone 1 to reach Zone2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Security rule&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;zone 2 and destination is zone 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Can you include a screenshot of the log and the security policy that you are talking about here? If I'm reading this correctly it sounds like what you are saying would make sense; if the security policy states traffic from 'zone 2' can reach 'zone 3' and then the log is identifying a source of 'zone 1' the policy shouldn't work for that traffic, as it doesn't match.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 03:22:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248972#M70822</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2019-02-06T03:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248977#M70825</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18618i60AFFC0C904E5D3B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="log.png" alt="log.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/18619iA5DC8A3BA928FEB6/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.png" alt="rule.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 03:44:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248977#M70825</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T03:44:00Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248978#M70826</link>
      <description>&lt;P&gt;i have attached the screenshot.&lt;/P&gt;&lt;P&gt;same rule works&amp;nbsp; fine if i just use my userd&amp;nbsp; id instead of group name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also i have modified the traffic flow&amp;nbsp; in earlier post sorry for that confusion.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 04:32:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248978#M70826</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T04:32:18Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248979#M70827</link>
      <description>&lt;P&gt;i tsested again by removing and adding the group name it worked now.&lt;/P&gt;&lt;P&gt;pretty strange behaviour sometimes it works and sometimes not&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 04:05:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248979#M70827</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T04:05:34Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248999#M70835</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Group-Mapping has default setting to poll the LDAP every 3600sec (one hour) to get the list of users for a given user group. I have seens lots of times when test user is put in the allowed user group on the AD and the user test his access immideately after that. But since the firewall is updating its information every hour, Palo Alto FW will not know that this user is already part the allowed group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am more interested in how do you optain the user id information? How do you perform the ip-to-user mapping, what is your source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other common issue I have seens is that ip-to-user mapping doesn't include the domain, while the user group-mapping does, and firewall again fail to match the user with the allowed user group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also what attribute are using to the username? For example user group-mapping is polling the UPN, but your ip-to-user mapping source is using CN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would say a good start will be to compare the outpus from&lt;BR /&gt;&amp;gt; show user ip-user-mapping all&lt;/P&gt;&lt;P&gt;&amp;gt; show user group name &amp;lt;full-cn-of-the-allowed-group&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 11:46:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/248999#M70835</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2019-02-06T11:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/249003#M70838</link>
      <description>&lt;P&gt;For userid we are using user id agent running on windows.&lt;/P&gt;&lt;P&gt;So PA talk to those user id agents and get the mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;for group mapping we use ldap also we use domain name with it&lt;/P&gt;&lt;P&gt;I have already run those commands and not much i can find in them&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;idle timeout for user id agent is 4 hours.&lt;/P&gt;&lt;P&gt;In group mappings i see update interval to default ?&lt;/P&gt;&lt;P&gt;should i increase the value here to like 4 hours?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 12:59:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/249003#M70838</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-06T12:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/249402#M70924</link>
      <description>&lt;P&gt;Nothing is changed in the config.&lt;/P&gt;&lt;P&gt;Group mapping is working fine from last 3 days&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 04:33:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/249402#M70924</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-08T04:33:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security policy not working with Group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/249587#M70977</link>
      <description>&lt;P&gt;still working fine with user group&lt;/P&gt;</description>
      <pubDate>Sun, 10 Feb 2019 17:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policy-not-working-with-group-mapping/m-p/249587#M70977</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-10T17:05:35Z</dc:date>
    </item>
  </channel>
</rss>

