- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-07-2020 10:49 AM
Having a bit of an issue but can't seem to pinpoint the solution.. When I go to add a security policy rule, under user, i cannot find specific users. However, when I go to the traffic monitor tab, I can see the user mapping is working from the User-ID agent, since I can find those same users there.
Not tied to a specific firewall as I'm not able to find these users on any firewall or panorama. If I add the user by pasting in the distinguished name in the security policy rule, it finds the user, but that is tedious
11-08-2020 10:38 AM
You said this was happening across multiple firewalls and your panorama instance right? So if it's not tied to a single device then it would appear far more likely it could potentially be an issue with how your pulling the group mapping.
11-07-2020 06:03 PM
Does the user include any sort of special characters or anything if it's the same users that are breaking?
11-08-2020 06:32 AM
Two of the users have periods (.) in their display name, but I have other users with this as well. Another user that doesn't show up is a new user, standard, nothing special about it. Seems to be a new issue because a new user that was created in the middle of the week shows up.
11-08-2020 10:38 AM
You said this was happening across multiple firewalls and your panorama instance right? So if it's not tied to a single device then it would appear far more likely it could potentially be an issue with how your pulling the group mapping.
11-08-2020 05:23 PM - edited 11-08-2020 05:35 PM
Correct, multiple firewalls/panorama. I originally thought it was group mapping, since I do a group include list and these users are not part of any of those groups. What threw me off is, other similar users do show up and they are not part of any of the groups that I include in the group mapping
That indeed was the issue though. Very weird that some of the other accounts that are not part of the group mapping were showing up. Thanks !
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!