<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User id connected but users name not showing in the security policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/431962#M95159</link>
    <description>&lt;P&gt;Thank you for posting message&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179347"&gt;@VishnuPS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I understand it correctly, you are not able to select source user while creating a new policy? Have you configured Group Mapping Setting? Here is a reference:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFQCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFQCA0&lt;/A&gt;&amp;nbsp;If yes, could you navigate to: Device &amp;gt; User Authentication &amp;gt; Group Mapping Settings &amp;gt; (Name) &amp;gt; Group Include List &amp;gt; Available Group, then type AD Group or User and try to search it by pressing Apply Filter button. If LDAP integration works well, the AD Group or User will appear in the list. All the AD Groups / Users that are available here, should be also selectable in new policy under source user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Sep 2021 08:15:26 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2021-09-06T08:15:26Z</dc:date>
    <item>
      <title>User id connected but users name not showing in the security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/431949#M95156</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have integrated AD to my PA NGFW. User id is showing connected but when I create any user based policy there is no users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried cleared user is cache, refresh etc. But still same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the below SS for reference&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VishnuPS_0-1630913490724.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/36156iE0D691DA419D438F/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="VishnuPS_0-1630913490724.png" alt="VishnuPS_0-1630913490724.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;useridd.log&lt;BR /&gt;2021-09-06 11:33:32&lt;BR /&gt;2021-09-06 11:33:32.523 +0530 connecting to ldap://[10.1.2.102]:389 ...&lt;BR /&gt;useridd.log&lt;BR /&gt;2021-09-06 11:33:32&lt;BR /&gt;2021-09-06 11:33:32.584 +0530 ldap cfg BLR_AD connected to 10.1.2.102:389(index 0)&lt;BR /&gt;useridd.log&lt;BR /&gt;2021-09-06 11:33:35&lt;BR /&gt;2021-09-06 11:33:35.123 +0530 pan_ha_is_sync_needed: needed=0, is_peer_up=0, state=0, peer_state=0&lt;BR /&gt;useridd.log&lt;BR /&gt;2021-09-06 11:33:35&lt;BR /&gt;2021-09-06 11:33:35.230 +0530 /opt/pancfg/cache/pan/VSYS_USER.db saved to disk, digest: 5153bfd3957d20d95f72742fd4c88034&lt;BR /&gt;useridd.log&lt;BR /&gt;2021-09-06 11:33:35&lt;BR /&gt;2021-09-06 11:33:35.633 +0530 Building userinfo.xml takes 0s&lt;BR /&gt;useridd.log&lt;BR /&gt;2021-09-06 11:33:36&lt;BR /&gt;2021-09-06 11:33:36.921 +0530 Error: pan_ldap_ctrl_search_device(pan_ldap_ctrl.c:1889): user_id database is not bound yet&lt;/P&gt;&lt;P&gt;Please help me to resolve this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 07:35:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/431949#M95156</guid>
      <dc:creator>VishnuPS</dc:creator>
      <dc:date>2021-09-06T07:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: User id connected but users name not showing in the security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/431962#M95159</link>
      <description>&lt;P&gt;Thank you for posting message&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179347"&gt;@VishnuPS&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I understand it correctly, you are not able to select source user while creating a new policy? Have you configured Group Mapping Setting? Here is a reference:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFQCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFQCA0&lt;/A&gt;&amp;nbsp;If yes, could you navigate to: Device &amp;gt; User Authentication &amp;gt; Group Mapping Settings &amp;gt; (Name) &amp;gt; Group Include List &amp;gt; Available Group, then type AD Group or User and try to search it by pressing Apply Filter button. If LDAP integration works well, the AD Group or User will appear in the list. All the AD Groups / Users that are available here, should be also selectable in new policy under source user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Pavel&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 08:15:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/431962#M95159</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-06T08:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: User id connected but users name not showing in the security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/432032#M95162</link>
      <description>&lt;P&gt;Hi Pavel,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We verified the configurations it's good only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I forgot you telling one thing, actually, I configured the user-id configuration from the panorama. I need to enable anything in the panorama.&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 09:52:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/432032#M95162</guid>
      <dc:creator>VishnuPS</dc:creator>
      <dc:date>2021-09-06T09:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: User id connected but users name not showing in the security policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/432058#M95164</link>
      <description>&lt;P&gt;Thank you for reply&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/179347"&gt;@VishnuPS&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I see. When it comes to Panorama and pushing user information, there is one difference compared to configuring it locally on Firewall. The format of AD information has to be in Distinguished Name (DN). Here is the KB for reference (Please go to point No.5):&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIOCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIOCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;After you configure it in this format, and push it to managed Firewall, the user information should be available in security policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Alternative solution would be to enable one Firewall that already has all information as a Master Device in the Device Group. Here is a KB for reference:&amp;nbsp;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tested both of the solutions and both were functional.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and Regards&lt;/P&gt;&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Sep 2021 13:05:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-connected-but-users-name-not-showing-in-the-security/m-p/432058#M95164</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2021-09-06T13:05:35Z</dc:date>
    </item>
  </channel>
</rss>

