<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: error user in group mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/365493#M88573</link>
    <description>&lt;P&gt;&lt;BR /&gt;hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Exactly, that is the problem.&amp;nbsp;The problem&amp;nbsp;appear with the reboot in the upgrade 9.1.5.&amp;nbsp;&lt;BR /&gt;The firewall has agentless user identification configured.&amp;nbsp; ¿Does you recommend me change the configuration of the server&amp;nbsp;type&amp;nbsp;&amp;nbsp;Microsoft Active Directory to&amp;nbsp;Microsoft Exchange?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2020 09:59:54 GMT</pubDate>
    <dc:creator>BigPalo</dc:creator>
    <dc:date>2020-11-25T09:59:54Z</dc:date>
    <item>
      <title>error user in group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/362960#M88316</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;After upgrading to &lt;STRONG&gt;8.1.X &amp;gt; 9.0.X&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;gt; 9.1.x.&lt;/STRONG&gt; we found that some ldap users do not check per user policies, only for ip politicies.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="tlid-language-bar ls-wrap"&gt;&lt;DIV class="tl-wrap"&gt;&lt;DIV class="tl-sugg"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;The firewall has no user-id configured, only tree server ldap.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;we check that the firewall recognizes the Ldap tree.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Is there any issue of incompatibility with the version?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="result-shield-container tlid-copy-target"&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Thanks.&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 13 Nov 2020 11:51:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/362960#M88316</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-11-13T11:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: error user in group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/363094#M88329</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Can you describe your issue a bit more. I'm not sure&amp;nbsp;&lt;EM&gt;exactly&amp;nbsp;&lt;/EM&gt;what you mean by "&lt;SPAN&gt;some ldap users do not check per user policies, only for ip politicies". Are you trying to get these users to match user based rulebase entries?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Nov 2020 01:09:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/363094#M88329</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2020-11-14T01:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: error user in group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/363250#M88342</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I explain the problem in more detail. After performing a firmware update from 8.1.X to 9.1.X we found the following problem.&lt;/P&gt;&lt;P&gt;From a PC we authenticate by ldap with the user "cafeteria", we observe in the monitor that the traffic machea by IP and not by user, which causes that it does not do mach due to the policies configured by user and this traffic is dropped&lt;/P&gt;&lt;P&gt;From the same PC, we try with another user "egonzalez" authenticates correctly and we verify in the monitor that it registers by user.&lt;/P&gt;&lt;P&gt;They do not have user-id agent configured. LDAP only with all group mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a bug with the version?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 09:24:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/363250#M88342</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-11-16T09:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: error user in group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/364533#M88480</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/85066"&gt;@BigPalo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you mean by "From a PC we authenticate by ldap with the user"?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Group mapping provide information for user group membership (which users are part of specific user group). This inforamtion is used if you want to use user groups (not individual users) in configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall still needs information for the actual user-to-ip mapping? What method are you using for to gather this information? If you don't use user-id agent, are you using Captive portal with Authentication policy?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 14:45:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/364533#M88480</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2020-11-20T14:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: error user in group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/364595#M88488</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Might want to search the release notes, however I have not seen this before. How are your user-id's getting processed, i.e. pointing at Domain Controllers, exchange, etc.? When the firewalls reboot, the user-id mappings get flushed if using agentless. So if the user-id doesnt see a new login, it will not show the mapping. I have seen a lot and hence I use Exchange logs rather than domain controllers since Outlook is constantly authenticating against the exchange servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 20:33:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/364595#M88488</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2020-11-20T20:33:49Z</dc:date>
    </item>
    <item>
      <title>Re: error user in group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/365479#M88570</link>
      <description>&lt;P&gt;Hi Alexander,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I explain you,&amp;nbsp;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;In the monitor we observe that sometimes the user's mach is observed and other times that of his IP.&amp;nbsp;&amp;nbsp;We have seen the following log when this happens:&amp;nbsp;&amp;nbsp;domain xxxx does not exist in group-mapping&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Currently the firewall has agentless user identification configured. The problem&amp;nbsp;&lt;SPAN class="gt-baf-term-text"&gt;&lt;SPAN class="gt-baf-cell gt-baf-word-clickable"&gt;appear with the upgrade 9.1.5.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;SPAN class="gt-baf-term-text"&gt;&lt;SPAN class="gt-baf-cell gt-baf-word-clickable"&gt;Thanks.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 09:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/365479#M88570</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-11-25T09:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: error user in group mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/365493#M88573</link>
      <description>&lt;P&gt;&lt;BR /&gt;hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Exactly, that is the problem.&amp;nbsp;The problem&amp;nbsp;appear with the reboot in the upgrade 9.1.5.&amp;nbsp;&lt;BR /&gt;The firewall has agentless user identification configured.&amp;nbsp; ¿Does you recommend me change the configuration of the server&amp;nbsp;type&amp;nbsp;&amp;nbsp;Microsoft Active Directory to&amp;nbsp;Microsoft Exchange?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 09:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/error-user-in-group-mapping/m-p/365493#M88573</guid>
      <dc:creator>BigPalo</dc:creator>
      <dc:date>2020-11-25T09:59:54Z</dc:date>
    </item>
  </channel>
</rss>

