<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Identification - 4.1 LDAP - AD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11712#M8593</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i saw the same behaviour. Support said it was a bug. To add the groups required i used the search feature above the LDAP tree. That seemed to work even though i could browse for the groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also keep in mind with the LDAP config the domain name i need to use the NETBIOS domain name not the full DNS name.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Nov 2011 00:18:20 GMT</pubDate>
    <dc:creator>supportOCA</dc:creator>
    <dc:date>2011-11-15T00:18:20Z</dc:date>
    <item>
      <title>User Identification - 4.1 LDAP - AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11711#M8592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have upgraded to 4.1 and added a ldap-server profile to the config so the firewall does the query instead of the user-id-agent.&lt;/P&gt;&lt;P&gt;When I go to group-mappings settings ( under user-identification ) and select the tab 'Group Include List',&lt;BR /&gt;I can see the whole AD-tree-structure, but I cannot view the last part: the group itself.&lt;/P&gt;&lt;P&gt;Has anybody seen this behavior ?&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Nov 2011 10:57:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11711#M8592</guid>
      <dc:creator>paulmeys</dc:creator>
      <dc:date>2011-11-14T10:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification - 4.1 LDAP - AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11712#M8593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i saw the same behaviour. Support said it was a bug. To add the groups required i used the search feature above the LDAP tree. That seemed to work even though i could browse for the groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also keep in mind with the LDAP config the domain name i need to use the NETBIOS domain name not the full DNS name.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 00:18:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11712#M8593</guid>
      <dc:creator>supportOCA</dc:creator>
      <dc:date>2011-11-15T00:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification - 4.1 LDAP - AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11713#M8594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apparantly it's working when you search for the EXACT name for the group.&lt;/P&gt;&lt;P&gt;but:&lt;/P&gt;&lt;P&gt;The normal listing works when you make your base "deep" enough in the ldap-server-profile.&lt;/P&gt;&lt;P&gt;so yes, I think it is a bug &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Nov 2011 10:34:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11713#M8594</guid>
      <dc:creator>paulmeys</dc:creator>
      <dc:date>2011-11-15T10:34:16Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification - 4.1 LDAP - AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11714#M8595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing the exact same behaviour - I am typing in the group names exactly and I do get a match. Unfortunately when I go to the command line and do "show user group name &amp;lt;group name&amp;gt;" I can get all to work apart from Domain Users. This group just returns an empty list which has meant the rules previously based on that - namely web access, have failed. This has obviously upset a few people...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The group lookup issue is a dissapointing bug - surely a complete lack of testing on something quite important...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 10:46:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-4-1-ldap-ad/m-p/11714#M8595</guid>
      <dc:creator>UKRB</dc:creator>
      <dc:date>2012-01-23T10:46:09Z</dc:date>
    </item>
  </channel>
</rss>

