<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID / group mapped incorrectly in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapped-incorrectly/m-p/10105#M7405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem was caused by wrong LDAP server properties. The FQDN of the domain was specified instead of the last portion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Mar 2012 17:31:14 GMT</pubDate>
    <dc:creator>ebo</dc:creator>
    <dc:date>2012-03-01T17:31:14Z</dc:date>
    <item>
      <title>User-ID / group mapped incorrectly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapped-incorrectly/m-p/10103#M7403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've wanted to block some sites for specific users and created an AD group on my W2K8 R2 DC. Unfortunatly I have some problems that I haven't encountered before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When checking the user I see the user is a member of my test group, so far so good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show user user-IDs match-user somedomain.local\test&lt;/P&gt;&lt;P&gt;User Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp; Groups&lt;BR /&gt;------------------------------------------------------------------&lt;BR /&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;somedomain.local\test&lt;/EM&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp; cn=test-block,ou=groups,ou=ou,dc=somedomain,dc=local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When checking the user/IP mapping on the firewall it lists the user:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; show user ip-user-mapping | match test&lt;/P&gt;&lt;P&gt;x.y.z.224&amp;nbsp;&amp;nbsp; AD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;somedomain.local\test&lt;/EM&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3475&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3475&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still all well. But when I browse to the blocked content, it isn't blocked. When adding the user &lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;somedomain\test&lt;/EM&gt;&lt;/SPAN&gt; to the security rule the user gets blocked!&lt;/P&gt;&lt;P&gt;But the username in this format is not mapped to the group, nor can I find the user in this short format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I configure somewhere the full domain name should be used and not the abbreviated one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 14:55:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapped-incorrectly/m-p/10103#M7403</guid>
      <dc:creator>ebo</dc:creator>
      <dc:date>2012-03-01T14:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID / group mapped incorrectly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapped-incorrectly/m-p/10104#M7404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The group mapping has an update interval to check for new group/member.&amp;nbsp; Maybe the new AD group is not learnt yet and need to wait for the update.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 16:00:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapped-incorrectly/m-p/10104#M7404</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-03-01T16:00:08Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID / group mapped incorrectly</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapped-incorrectly/m-p/10105#M7405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem was caused by wrong LDAP server properties. The FQDN of the domain was specified instead of the last portion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 17:31:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapped-incorrectly/m-p/10105#M7405</guid>
      <dc:creator>ebo</dc:creator>
      <dc:date>2012-03-01T17:31:14Z</dc:date>
    </item>
  </channel>
</rss>

