<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Authentication -  Users are not matching with groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/309919#M80275</link>
    <description>&lt;P&gt;Hi, Matt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I have deleted it last week. Now, my "user domain" space is blank. I have followed the documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have both the groups and users un NETBIOS format (netbios\group, netbios\user). But it continues without matching.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thought was the policy, but when I change the specific group to "Known User" the policy starts to log traffic. So based on that I conclude that the FW is not seeing the users within the group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 22:28:08 GMT</pubDate>
    <dc:creator>iscott</dc:creator>
    <dc:date>2020-02-06T22:28:08Z</dc:date>
    <item>
      <title>Authentication -  Users are not matching with groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/309859#M80265</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem with authentication. I have configured a PAN integrated agent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see users authenticated. At the same time, the firewall is getting the groups from AD. But for some reason, the users are not matching with the groups. So the policy based on the group that I configure is not logging traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users and groups are in NETBIOS format.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 17:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/309859#M80265</guid>
      <dc:creator>iscott</dc:creator>
      <dc:date>2020-02-06T17:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication -  Users are not matching with groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/309912#M80273</link>
      <description>&lt;P&gt;I recently had an issue where I could see my AD groups and apply them to policies.. but it seemed like the users were not being enumerated and consequently the policy was not being applied. It turned out to be a domain name mismatch.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My AD groups as appearing in policy looked like this:&amp;nbsp; domain\user&lt;/P&gt;&lt;P&gt;But my users were being enumerated as: domain.local\user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ended having to change the remove the ".local" domain suffix in the user ID group mapping setting.&amp;nbsp; Once that happened, the policies started to apply to the group members themselves. Not sure if this is what you are seeing, but a place to check!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Device &amp;gt; User Identification &amp;gt; Group Mapping Setting&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 22:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/309912#M80273</guid>
      <dc:creator>MattRathbun</dc:creator>
      <dc:date>2020-02-06T22:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication -  Users are not matching with groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/309919#M80275</link>
      <description>&lt;P&gt;Hi, Matt.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I have deleted it last week. Now, my "user domain" space is blank. I have followed the documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have both the groups and users un NETBIOS format (netbios\group, netbios\user). But it continues without matching.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thought was the policy, but when I change the specific group to "Known User" the policy starts to log traffic. So based on that I conclude that the FW is not seeing the users within the group.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 22:28:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/309919#M80275</guid>
      <dc:creator>iscott</dc:creator>
      <dc:date>2020-02-06T22:28:08Z</dc:date>
    </item>
    <item>
      <title>Re: Authentication -  Users are not matching with groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/311244#M80557</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;About this case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't know why in Group Mapping configuration was a "sAMAccountName" configured in the Group Objects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Were necessary to create a new Group Mapping with the "Search Filter" blank.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iscott_0-1581691930988.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/23970i03F99EAF8FA6395C/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="iscott_0-1581691930988.png" alt="iscott_0-1581691930988.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It began to work after that change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 14:50:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/authentication-users-are-not-matching-with-groups/m-p/311244#M80557</guid>
      <dc:creator>iscott</dc:creator>
      <dc:date>2020-02-14T14:50:35Z</dc:date>
    </item>
  </channel>
</rss>

