- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-06-2020 09:40 AM
Hello,
I have a problem with authentication. I have configured a PAN integrated agent.
I can see users authenticated. At the same time, the firewall is getting the groups from AD. But for some reason, the users are not matching with the groups. So the policy based on the group that I configure is not logging traffic.
Users and groups are in NETBIOS format.
Regards,
02-14-2020 06:50 AM
Hello,
About this case.
I don't know why in Group Mapping configuration was a "sAMAccountName" configured in the Group Objects.
Were necessary to create a new Group Mapping with the "Search Filter" blank.
It began to work after that change.
Regards,
02-06-2020 02:13 PM
I recently had an issue where I could see my AD groups and apply them to policies.. but it seemed like the users were not being enumerated and consequently the policy was not being applied. It turned out to be a domain name mismatch.
My AD groups as appearing in policy looked like this: domain\user
But my users were being enumerated as: domain.local\user
I ended having to change the remove the ".local" domain suffix in the user ID group mapping setting. Once that happened, the policies started to apply to the group members themselves. Not sure if this is what you are seeing, but a place to check!
Device > User Identification > Group Mapping Setting
02-06-2020 02:26 PM - edited 02-06-2020 02:28 PM
Hi, Matt.
Thanks for your response.
Yes, I have deleted it last week. Now, my "user domain" space is blank. I have followed the documentation.
I have both the groups and users un NETBIOS format (netbios\group, netbios\user). But it continues without matching.
Thought was the policy, but when I change the specific group to "Known User" the policy starts to log traffic. So based on that I conclude that the FW is not seeing the users within the group.
Regards,
02-14-2020 06:50 AM
Hello,
About this case.
I don't know why in Group Mapping configuration was a "sAMAccountName" configured in the Group Objects.
Were necessary to create a new Group Mapping with the "Search Filter" blank.
It began to work after that change.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!