<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID - Active Directory Keeps Sending Domain DNS and NetBIOS DNS in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/356081#M87616</link>
    <description>&lt;P&gt;J'ai finalement trouvé la cause de ce problème d'authentification...&lt;/P&gt;&lt;P&gt;Mon domaine a un DN enregistré dans la foret, il faut donc créé un connecteur ldap vers cet autre domaine, ajouter un mapping de groupe vers ce domaine basé sur le même groupe Active Directory.&lt;/P&gt;&lt;P&gt;Une fois ceci effectué, tous les utilisateurs sont bien convertis en netbiosdomain\user&lt;/P&gt;&lt;P&gt;On a ce problème d'authentification sous la forme user@dnsdomain pour une machine quand paloalto a besoin de l'authentifier et que le domaine actuel est enregistré dans un autre domaine au niveau du DN du domaine.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 14:18:54 GMT</pubDate>
    <dc:creator>jlesquerpit</dc:creator>
    <dc:date>2020-10-13T14:18:54Z</dc:date>
    <item>
      <title>User-ID - Active Directory Keeps Sending Domain DNS and NetBIOS DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/355215#M87518</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having a headache of an issue lately and I believe it to be an issue on the customer environment rather than a setting configuration on the firewall, or software issue in PAN-OS e.g.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've little experience with enterprise active directory so I learn as I go.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the moment, customer has been using the Domain DNS for User Domain settings on Authentication Profiles and Group Mappings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I plan to change this and make sure to use the NetBIOS in place of the domain DNS for User Domain settings in Authentication Profiles and Group Mapping settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN-OS 9.0.8&lt;/P&gt;&lt;P&gt;Global Protect 5.1.3&lt;/P&gt;&lt;P&gt;Windows Server: Not Sure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the customers environment, certain subnets, be it wired or wireless,&amp;nbsp; the ip-user-mapping are picked up as sometimes lan.corp.com/user or corp/user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Therefore, an ip-user-mapping of lan.corp.com/user isn't recognized as being part of the AD group corp/webaccess&amp;nbsp; and security rule is never hit.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Same user will then remove the wired connection, will be picked up on a different ip-address via Wifi but is now seen on the firewall as corp/user, is seen inside AD group corp/webaccess and hits the rule, gaining web access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*&lt;/P&gt;&lt;P&gt;*&lt;/P&gt;&lt;P&gt;Again issue happens when users try to authenticate from home via Global Protect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Verifying with command [ &amp;gt; tail follow yes mp-log authd ] users authentication will fail because lan.corp.com/user is not inside AD group globalprotect .... user will try again and again until eventually they are picked up as corp/user.&lt;/P&gt;&lt;P&gt;*&lt;/P&gt;&lt;P&gt;*&lt;/P&gt;&lt;P&gt;I've searched almost all of LiveCommunity, Fuel User Group and Support Portal Knowledgebase to see if this has come up before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most articles state the requirement of using NetBIOS in place of Domain DNS but nothing stating what steps the customer should do to verify domain mapping and AD is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 14:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/355215#M87518</guid>
      <dc:creator>SirchRettop</dc:creator>
      <dc:date>2020-10-08T14:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - Active Directory Keeps Sending Domain DNS and NetBIOS DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/355341#M87530</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/110661"&gt;@SirchRettop&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It really sounds like you haven't set a&amp;nbsp;&lt;EM&gt;Primary Username&amp;nbsp;&lt;/EM&gt;on the firewall since the introduction of multiple username formats with PAN-OS 8.1. I'd look at your group mappings and verify that your User Attributes are actually setup properly.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Oct 2020 02:29:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/355341#M87530</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-10-09T02:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - Active Directory Keeps Sending Domain DNS and NetBIOS DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/355762#M87580</link>
      <description>&lt;P&gt;J'ai le même problème, certains utilisateurs sont identifiés comme&amp;nbsp;netbiosdomain\user et dnsdomain\user&lt;/P&gt;&lt;P&gt;Quand ils sont reconnus comme netbiosdomaine\user, la règle de sécurité basée sur le groupe AD est bien appliquée.&lt;/P&gt;&lt;P&gt;Quand ils sont reconnus comme dnsdomain\user la règle n'est pas appliquée à l'utilisateur.&lt;/P&gt;&lt;P&gt;Quand je vais voir dans monitoring user-id, je vois que l'utilisateur est reconnu en dnsdomain\user quand la source retourne le user sous la forme user@dnsdomain. C'est ce qui pose problème. Pourquoi la source retourne &lt;A href="mailto:user@dnsdomain.." target="_blank"&gt;user@dnsdomain..&lt;/A&gt;. Comment faire pour ne pas avoir ce retour sous la forme &lt;A href="mailto:user@dnsdomain" target="_blank"&gt;user@dnsdomain&lt;/A&gt;&amp;nbsp;mais n'avoir que le retour sous la forme netbiosdomain\user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2020 10:33:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/355762#M87580</guid>
      <dc:creator>jlesquerpit</dc:creator>
      <dc:date>2020-10-12T10:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - Active Directory Keeps Sending Domain DNS and NetBIOS DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/356081#M87616</link>
      <description>&lt;P&gt;J'ai finalement trouvé la cause de ce problème d'authentification...&lt;/P&gt;&lt;P&gt;Mon domaine a un DN enregistré dans la foret, il faut donc créé un connecteur ldap vers cet autre domaine, ajouter un mapping de groupe vers ce domaine basé sur le même groupe Active Directory.&lt;/P&gt;&lt;P&gt;Une fois ceci effectué, tous les utilisateurs sont bien convertis en netbiosdomain\user&lt;/P&gt;&lt;P&gt;On a ce problème d'authentification sous la forme user@dnsdomain pour une machine quand paloalto a besoin de l'authentifier et que le domaine actuel est enregistré dans un autre domaine au niveau du DN du domaine.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 14:18:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/356081#M87616</guid>
      <dc:creator>jlesquerpit</dc:creator>
      <dc:date>2020-10-13T14:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - Active Directory Keeps Sending Domain DNS and NetBIOS DNS</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/356698#M87676</link>
      <description>&lt;P&gt;I managed to solve the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tweaked the config and used the NetBIOS dns in place of the Domain dns in any setting where it asks for the 'Domain' input e.g. Group Mapping and Authentication Profiles&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Users are now always successfully matched in a security rule and also can authenticate over Global Protect without previous intermittent failures&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 08:07:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-active-directory-keeps-sending-domain-dns-and-netbios/m-p/356698#M87676</guid>
      <dc:creator>SirchRettop</dc:creator>
      <dc:date>2020-10-16T08:07:50Z</dc:date>
    </item>
  </channel>
</rss>

