Authentication - Users are not matching with groups

Reply
Highlighted
L1 Bithead

Authentication - Users are not matching with groups

Hello, 

 

I have a problem with authentication. I have configured a PAN integrated agent. 

 

I can see users authenticated. At the same time, the firewall is getting the groups from AD. But for some reason, the users are not matching with the groups. So the policy based on the group that I configure is not logging traffic.

 

Users and groups are in NETBIOS format. 

 

Regards,  

 

 


Accepted Solutions
Highlighted
L1 Bithead

Re: Authentication - Users are not matching with groups

Hello,

 

About this case.

 

I don't know why in Group Mapping configuration was a "sAMAccountName" configured in the Group Objects.

 

Were necessary to create a new Group Mapping with the "Search Filter" blank. 

 

iscott_0-1581691930988.png

 

It began to work after that change.

 

Regards,

View solution in original post


All Replies
Highlighted
L0 Member

Re: Authentication - Users are not matching with groups

I recently had an issue where I could see my AD groups and apply them to policies.. but it seemed like the users were not being enumerated and consequently the policy was not being applied. It turned out to be a domain name mismatch. 

 

My AD groups as appearing in policy looked like this:  domain\user

But my users were being enumerated as: domain.local\user

 

I ended having to change the remove the ".local" domain suffix in the user ID group mapping setting.  Once that happened, the policies started to apply to the group members themselves. Not sure if this is what you are seeing, but a place to check!

 

Device > User Identification > Group Mapping Setting 

Highlighted
L1 Bithead

Re: Authentication - Users are not matching with groups

Hi, Matt. 

 

Thanks for your response. 

 

Yes, I have deleted it last week. Now, my "user domain" space is blank. I have followed the documentation.

 

I have both the groups and users un NETBIOS format (netbios\group, netbios\user). But it continues without matching. 

 

Thought was the policy, but when I change the specific group to "Known User" the policy starts to log traffic. So based on that I conclude that the FW is not seeing the users within the group. 

 

Regards, 

Highlighted
L1 Bithead

Re: Authentication - Users are not matching with groups

Hello,

 

About this case.

 

I don't know why in Group Mapping configuration was a "sAMAccountName" configured in the Group Objects.

 

Were necessary to create a new Group Mapping with the "Search Filter" blank. 

 

iscott_0-1581691930988.png

 

It began to work after that change.

 

Regards,

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!