Using the API to refresh the group mapping cache

Showing results for 
Show  only  | Search instead for 
Did you mean: 

Using the API to refresh the group mapping cache

L3 Networker


Is there a way using the Rest API to refresh the group mapping cache?

We're using AD groups where possible to control access in policies, and the system refreshes every hour but sometimes this is too long.

I have the CLI command to do this but would like to set this up with the API if possible.




Hi, Debug commands are not among the <op> commands that are exposed via the API.  If you search for PAN-Perl there is an expect based CLI tool for remotely executing CLI commands on the firewall that will work.

oh snap!

How come?

There are lots of debug commands that can impact the performance of the device significantly so they limit what is exposed, the correct handling of this is to map it to a corresponding <op> command that makes sense like request user-id refresh (dp-uid-gid | group-mapping | user-id).  I think that is an excellent Feature Request!  I can bring it up to the User-ID Product Manager if you would like.

I did try something similar in the API browser to see what works but it didn't come back with anything useful

Thanks anyways Smiley Happy

Yes, can you please put that in as a Feature Request.  Let me know if I should also bring it to the attention of my local PAN guys.


Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!