Our PA 4.1 has problems mapping entries received from user-ID agent and LDAP queries.
show user ip-user-mapping command produces following output:
192.168.1.1 AD grybai\vltr12345678
Here grybai is our NetBIOS domain name for domain and vltr12345678 is sAMAccountName attribute of user object in LDAP.
However command show user user-IDs (which shows information received by PA from LDAP queries) for the same user shows:
email@example.com vsys1 cn=b8710 users,ou=email,ou=groups,dc=corp,dc=grybaigroup,dc=eu
where firstname.lastname@example.org is userPrincipalName attribute for the same user.
During policy configuration PA web interface gives list of users in email@example.com , however such policy doesn't match traffic for that user. Policy with group also doesn't match traffic for that user.
If add policy with grybai\vltr12345678 user (I have to manually type user name during policy configuration), it matches traffic for that user.
LDAP server is configured as type active-directory, under "Group mapping settings" username field is configured as sAMAccountName (default). Tried to change that value with no lock.
Any ideas how to fix it?
For the group errors;
In the LDAP config, under active directory name, make sure this setting is in NETBIOS format not DNS name.
eg DOMAINNAME and not domainname.com
In the User-ID_Upgrade_4.1 it is quite clearly noted not configure any domain unless device is working in multidomain environment, so we don't configured any. Before posting this post I tried to configure both netbios and dns domains without any luck.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!