<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User group Mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/363083#M88323</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162050"&gt;@zamiedu&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can override the domain detected by the group mapping. Under the group mapping profile define "user domain" to match what you have for the ip-user-mapping:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AlexanderAstardzhiev_0-1605299455264.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28625iC1580576672668CF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AlexanderAstardzhiev_0-1605299455264.png" alt="AlexanderAstardzhiev_0-1605299455264.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Nov 2020 20:32:16 GMT</pubDate>
    <dc:creator>aleksandar.astardzhiev</dc:creator>
    <dc:date>2020-11-13T20:32:16Z</dc:date>
    <item>
      <title>User group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/362573#M88287</link>
      <description>&lt;P&gt;Wndows logon user name is ABC\xyz, and the user id fetched from AD group is ABC.local\xyz, and because of that the traffic is not hitting the configured rule. Any workaround to fix this?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 12:39:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/362573#M88287</guid>
      <dc:creator>zamiedu</dc:creator>
      <dc:date>2020-11-12T12:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: User group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/362694#M88293</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because the UserID FETCHED this information, it is coming from the AD server, and not created/caused by the FW.&lt;/P&gt;
&lt;P&gt;Could you change the policy to match what is being received by the AD server?&lt;/P&gt;
&lt;P&gt;That is the suggestion.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are you using the built in UserID agent or the standalone (or both?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Nov 2020 16:46:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/362694#M88293</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2020-11-12T16:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: User group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/363083#M88323</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162050"&gt;@zamiedu&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can override the domain detected by the group mapping. Under the group mapping profile define "user domain" to match what you have for the ip-user-mapping:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AlexanderAstardzhiev_0-1605299455264.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/28625iC1580576672668CF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AlexanderAstardzhiev_0-1605299455264.png" alt="AlexanderAstardzhiev_0-1605299455264.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Nov 2020 20:32:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/363083#M88323</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-11-13T20:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: User group Mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/363213#M88340</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/162050"&gt;@zamiedu&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Usually, the domain normalization is done to normalize the domain name to NetBIOS name.&lt;/P&gt;&lt;P&gt;If you don't have a user domain explicitly mentioned in the authentication profile or group mapping, you can add the NetBIOS name manually as a workaround.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 06:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-mapping/m-p/363213#M88340</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2020-11-16T06:24:34Z</dc:date>
    </item>
  </channel>
</rss>

