Authentication - Users are not matching with groups

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Authentication - Users are not matching with groups

L2 Linker

Hello, 

 

I have a problem with authentication. I have configured a PAN integrated agent. 

 

I can see users authenticated. At the same time, the firewall is getting the groups from AD. But for some reason, the users are not matching with the groups. So the policy based on the group that I configure is not logging traffic.

 

Users and groups are in NETBIOS format. 

 

Regards,  

 

 

1 accepted solution

Accepted Solutions

Hello,

 

About this case.

 

I don't know why in Group Mapping configuration was a "sAMAccountName" configured in the Group Objects.

 

Were necessary to create a new Group Mapping with the "Search Filter" blank. 

 

iscott_0-1581691930988.png

 

It began to work after that change.

 

Regards,

View solution in original post

3 REPLIES 3

L1 Bithead

I recently had an issue where I could see my AD groups and apply them to policies.. but it seemed like the users were not being enumerated and consequently the policy was not being applied. It turned out to be a domain name mismatch. 

 

My AD groups as appearing in policy looked like this:  domain\user

But my users were being enumerated as: domain.local\user

 

I ended having to change the remove the ".local" domain suffix in the user ID group mapping setting.  Once that happened, the policies started to apply to the group members themselves. Not sure if this is what you are seeing, but a place to check!

 

Device > User Identification > Group Mapping Setting 

Hi, Matt. 

 

Thanks for your response. 

 

Yes, I have deleted it last week. Now, my "user domain" space is blank. I have followed the documentation.

 

I have both the groups and users un NETBIOS format (netbios\group, netbios\user). But it continues without matching. 

 

Thought was the policy, but when I change the specific group to "Known User" the policy starts to log traffic. So based on that I conclude that the FW is not seeing the users within the group. 

 

Regards, 

Hello,

 

About this case.

 

I don't know why in Group Mapping configuration was a "sAMAccountName" configured in the Group Objects.

 

Were necessary to create a new Group Mapping with the "Search Filter" blank. 

 

iscott_0-1581691930988.png

 

It began to work after that change.

 

Regards,

  • 1 accepted solution
  • 5317 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!