About User-ID configurate

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

About User-ID configurate

L2 Linker



My User-ID agent was successfully linked to PA and I also saw Source User in the log.



I then configured the LDAP and group mapping and applied its source user to the new policy and wanted to verify that it worked.


I found that the PAs were all using the old policy (LAN_to_WAN) and it seemed that the PAs were not catching the source users to use new policy (Test_User)...




Any help is appreciate.




Cyber Elite
Cyber Elite

Hi @young19918 ,


When a user does not match a group, it is almost always is because the username format does not match.


  1. Show the username format in the IP-mappings with the CLI "show user ip-user-mapping all" command.
  2. Show the username format in the group mappings with the CLI "show user group list" and "show user group name <group>" commands.  Use quotes if your group name has spaces.
  3. Verify that the format is the same for the user in both outputs.

If the domain does not match or is missing, you can manually configure the User Domain (Domain Override) for the user-IP mappings in the authentication profile or for the user-group mappings under the Server Profile tab.


If the username format is different (e.g., domain\user = sAMAccountName vs. user@domain = userPrincipalName) you can modify the Primary Username under the User and Group Attributes tab in the Group Mapping settings.  Or, you can change the Username Modifier in the authentication profile.





Help the community: Like helpful comments and mark solutions.
  • 1 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!