<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access problems via Globalprotect with AD group. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386443#M90252</link>
    <description>&lt;P&gt;What do you mean "on both gateways enter via cli ..."? I must have explained it wrong, the GP gateways are related to internet links. I can access the VPN via the IP of one provider or the IP of another provider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The command "show user group list" showed me that the list is very long, but I can identify the DN using "show user group list | match &amp;lt;group_name&amp;gt;".&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;However when I use the command "show user group name &amp;lt;group_name&amp;gt;" the result is always the same regardless of the group you are querying: User group 'group_name' does not exist or does not have members&lt;/P&gt;</description>
    <pubDate>Wed, 17 Feb 2021 18:08:11 GMT</pubDate>
    <dc:creator>Amaro123</dc:creator>
    <dc:date>2021-02-17T18:08:11Z</dc:date>
    <item>
      <title>Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386371#M90243</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I am relatively new to Palo Alto solutions and I face a problem that has been going on for over a week. Could anyone help me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the scenario:&lt;BR /&gt;- I have gateways 01 and 02 for the GlobalProtect.&lt;BR /&gt;- AD groups called Grupo1 and Grupo2.&lt;BR /&gt;- Test user named Fred.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When user Fred is in Group1 he has normal access to the environment through the two gateways.&lt;BR /&gt;When that same user is in Group2 he has normal access only through gateways 01. If you use 02 he does not access anything.&lt;/P&gt;&lt;P&gt;I reviewed the LDAP settings but did not find any unique references to the groups I have.&lt;/P&gt;&lt;P&gt;What can I not be seeing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 14:28:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386371#M90243</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-02-17T14:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386416#M90248</link>
      <description>&lt;P&gt;the group settings can be found in Device\User Identification\Group Mapping\Group include&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and try the following...&lt;/P&gt;&lt;P&gt;on both gateways enter via cli...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and compare to ensure you are checking the same groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;then on both gateways enter..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group name&amp;nbsp; " enter group name from above here"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do this for both groups and check to see all members are displayed for both gateways,&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 16:58:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386416#M90248</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-17T16:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386443#M90252</link>
      <description>&lt;P&gt;What do you mean "on both gateways enter via cli ..."? I must have explained it wrong, the GP gateways are related to internet links. I can access the VPN via the IP of one provider or the IP of another provider.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The command "show user group list" showed me that the list is very long, but I can identify the DN using "show user group list | match &amp;lt;group_name&amp;gt;".&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;However when I use the command "show user group name &amp;lt;group_name&amp;gt;" the result is always the same regardless of the group you are querying: User group 'group_name' does not exist or does not have members&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 18:08:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386443#M90252</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-02-17T18:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386447#M90254</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29975i69FFFA538F6DAB43/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Feb 2021 18:16:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386447#M90254</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-02-17T18:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386521#M90266</link>
      <description>&lt;P&gt;you have not used the "Included Groups" option.&lt;/P&gt;&lt;P&gt;This will force the firewall to collect all information for every group within your AD.&lt;/P&gt;&lt;P&gt;The firewall has limits on how many groups it can access and although this may not be the issue here I would still only include the required groups that you actually need to interrogate. this will also help with future diagnostics when using multiple groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will also allow you to use "show user group name"&amp;nbsp; and return valid entries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;snippet from PA&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="MickBall_0-1613636445260.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29982iCB0422DF7A1C8ACA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="MickBall_0-1613636445260.png" alt="MickBall_0-1613636445260.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 08:21:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386521#M90266</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-18T08:21:11Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386522#M90267</link>
      <description>&lt;P&gt;OK just re-read your reply, are both of these gateways on the same firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If so then it should be OK as we have a similar setup of multi gateways on same firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;are both gateways using the same policy, or do you have a policy for each zone?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 08:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386522#M90267</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-18T08:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386673#M90288</link>
      <description>&lt;P&gt;Thanks for the tip with "Included Groups". It can be an interesting point for improvements and I will study the possibility of adjusting it!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, both are on the same firewall and using the same policy.&lt;/P&gt;&lt;P&gt;Even with the user having problems, I see the communication attempt, but the log is presented as the "incomplete" status.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 408px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/29996i477650692AF2E54C/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2021 19:47:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386673#M90288</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-02-18T19:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386794#M90300</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169083"&gt;@Amaro123&lt;/a&gt;&amp;nbsp; is the communication attempt you are seeing allowed or denied?&amp;nbsp; &amp;nbsp;I would imagine that it's allowed or the sate would be not-applicable.&amp;nbsp; it may help if you paste log snippet.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Feb 2021 09:35:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386794#M90300</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2021-02-19T09:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386903#M90318</link>
      <description>&lt;P&gt;Hello&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;They are allowed, but in Application the status is "incomplete".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rule.PNG" style="width: 927px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30003i552FF4E674EA90FA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="rule.PNG" alt="rule.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;I used the command "show users user-ids match-user &amp;lt;user.name&amp;gt;" for the user who has been doing the tests and he recognizes the group I mention here in the example that presents the problem. In this case it is the third in the print list.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="UserName lia-user-name lia-user-rank-L7-Applicator lia-component-message-view-widget-author-username"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="show user user-ids.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30004iBF779B0E4BDF1DFB/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="show user user-ids.PNG" alt="show user user-ids.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="lia-message-author-rank lia-component-author-rank lia-component-message-view-widget-author-rank"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 19 Feb 2021 18:37:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/386903#M90318</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-02-19T18:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387080#M90337</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169083"&gt;@Amaro123&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"When user Fred is in Group1 he has normal access to the environment through the two gateways.&lt;BR /&gt;When that same user is in Group2 he has normal access only through gateways 01. If you use 02 he does not access anything."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having the above in mind and the logs you provide it looks to be like routing problem.&lt;/P&gt;&lt;P&gt;I am assuming that the two gateways are assigning different IP pools to the connected users, but do they assign different range based on the user group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can imagine that gateway01 and 02 are assinging differen IP addresses based on the group membership. So when user is assigned to Group2 and connects to gateway02 he is assigned with ip address that your internal network doesn't route properly. If you look at the log details (the magnifying glass on the very left of your log entry you sent earlier) you will probably see that traffic is only in one direction - packets/bytes received will be zero. Or if you have internal firewall that is blocking the range assigned to users in group2 connected to gateway2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In short - check what IP range is assigned when connected any gateway with any group and check if your internal network handle these ip ranges the same way.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 08:44:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387080#M90337</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-02-22T08:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387620#M90400</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First of all, thanks for your interest in helping!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Initially I also thought about routing, but the pools in the group that has a problem use the same subnet. All others use different subnets. See the print.&lt;/P&gt;&lt;P&gt;Regarding the details of the logs you commented, there is really no answer from the other end.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30050i8A884E8743FBB55B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 18:34:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387620#M90400</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-02-24T18:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387754#M90420</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/169083"&gt;@Amaro123&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure that using same IP pool for the two different gateways is good (not sure what word to use..) configuration.&lt;/P&gt;&lt;P&gt;I believe I have read somewhere while ago that if you assing&amp;nbsp; same IP pool to two different agent config/user group this could cause IP conflict and firewall can assign the same ip to two different users. FW is monitoring the IP allocation "locally" for each agent config, without being aware of the all the pools configured on the GP gateway. I believe I read this mainly for same ip pool under one gateway, but in my humble opinion it should be a problem with two separate gateways. When you assign IP pool to gateway agent config FW will create static route (or split it to multiple static routes) pointing to the tunnel interface assosiated with gateway. If you assign same IP pool to two different gateways, I assume FW will try to create same static routes pointing to two different tunnel interfaces. Which could explain your issue -fw has static routes for IP pools pointing to tunnle.1 and tunnel.2, when you connect to gateway1 traffic is working as return traffic is taking first route. But when you connect to gateway2 return traffic is routed to wrong tunnel interface and traffic doesn't reach the user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In any case I really don't like the idea of having same IP pool assigned to more than one gateway agent config (no matter if it is on same gateway or different). I just think FW will have problems with that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if you want, before trying with different IP pool, create a packet capture&lt;/P&gt;&lt;P&gt;- listening on the inside interface (the lan behind the fw)&lt;/P&gt;&lt;P&gt;- try connect to gateway2 with problematic group and generate traffic to inside (simple ping will do the trick)&lt;/P&gt;&lt;P&gt;- check the capture - do you see replies hitting the inside interface ( this will confirm that you have bi-directional traffic behind the firewall and that fw is receiving all the traffic, but after that it doesn't route properly or dropping return traffic)&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 08:40:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387754#M90420</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-02-25T08:40:50Z</dc:date>
    </item>
    <item>
      <title>Re: Access problems via Globalprotect with AD group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387824#M90429</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Changing the subnet to a different one had no effect. I had already done this test and the scenario was the same.&lt;BR /&gt;And there is no other device for routing connected to the firewall.&lt;/P&gt;&lt;P&gt;Yesterday the firewall was rebooted by a power failure in the rack where it is and I did new tests today. Even if I am not successful in ping or telnet communications, I can see by the details of the logs that there is an answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30068iABC996C2D8B8EBCA/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 18:07:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/access-problems-via-globalprotect-with-ad-group/m-p/387824#M90429</guid>
      <dc:creator>Amaro123</dc:creator>
      <dc:date>2021-02-25T18:07:22Z</dc:date>
    </item>
  </channel>
</rss>

