<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Groups in Firewall Policy - Inconsistent Behaviour in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12266#M8982</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running 4.1.10 and the cosmetic bug still exists.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Feb 2013 22:02:38 GMT</pubDate>
    <dc:creator>CRT-Capital</dc:creator>
    <dc:date>2013-02-12T22:02:38Z</dc:date>
    <item>
      <title>AD Groups in Firewall Policy - Inconsistent Behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12262#M8978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have two issues with managing firewall policies when using AD groups; running 4.1.7 - so am using the 'on-hardware' group retrieval rather than the PAN Agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) When adding new groups to be mapped they do not appear in the GUI i.e. cannot be selected for a policy from the 'drop down' selector.&amp;nbsp; This will usually fix itself after a random amount of time - hours or days (and this occurs even when, using the command line interface, I have confirmed that the group is being populated and tracked by the firewall using the &lt;STRONG&gt;show users groups name&lt;/STRONG&gt; command etc).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The Palo policy UI seems to randomly display the groups (and users) in either AD format or X500(?) format i.e. sometimes it uses &lt;STRONG&gt;acme\auser&lt;/STRONG&gt; and othertimes it uses &lt;STRONG&gt;cn=auser, ou=users, o=acme&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This occurs both on the PA firewalls and our Panorama install.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's annoying more than anything, as we can usually work our way round the issue, but understanding why it doesn't behave consistently would be a bonus!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 16:03:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12262#M8978</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-10-10T16:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups in Firewall Policy - Inconsistent Behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12263#M8979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've the same trouble with PANOS version 4.1.9.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 16:09:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12263#M8979</guid>
      <dc:creator>PYNICOLAS</dc:creator>
      <dc:date>2012-10-10T16:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups in Firewall Policy - Inconsistent Behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12264#M8980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've just got a little further forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My PA's are in HA pairs and it looks as if maybe only the active device will update the GUI etc to make the new groups visible.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As (in the scenario I have at the moment) the passive PA is the one set as the master device for that group in Panorama, it looks as if Panorama won't make it available in the policy section either.&amp;nbsp; I have just switched the master device to the currently active PA and now I can select the newly mapped group in the Panorama policy, and push to the HA pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if the policy will work properly on the (currently) passive box if it is promoted to live though....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or - it was just luck that the GUI decided to update at the time I was testing that scenario!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 16:16:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12264#M8980</guid>
      <dc:creator>apackard</dc:creator>
      <dc:date>2012-10-10T16:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups in Firewall Policy - Inconsistent Behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12265#M8981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've not seen the new group mapping issue before but suspect that the config push from Panorama may also replicate the change to the other node (including the new group) although you may want to log a call with support to confirm correct functionality but also so that they can keep track of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user issue (acme\auser vs cn=auser) described is something that will be addressed in 4.1.9 - this was identified as a cosmetic issue and does not impact functionality. For clarity, 4.1.8 is the latest code and was released mid September.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Oct 2012 21:38:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12265#M8981</guid>
      <dc:creator>ND</dc:creator>
      <dc:date>2012-10-11T21:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: AD Groups in Firewall Policy - Inconsistent Behaviour</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12266#M8982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm running 4.1.10 and the cosmetic bug still exists.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2013 22:02:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-groups-in-firewall-policy-inconsistent-behaviour/m-p/12266#M8982</guid>
      <dc:creator>CRT-Capital</dc:creator>
      <dc:date>2013-02-12T22:02:38Z</dc:date>
    </item>
  </channel>
</rss>

