Can't find user for security policy rule

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Can't find user for security policy rule

L3 Networker

Having a bit of an issue but can't seem to pinpoint the solution..   When I go to add a security policy rule, under user, i cannot find specific users.   However, when I go to the traffic monitor tab, I can see the user mapping is working from the User-ID agent, since I can find those same users there.

 

Not tied to a specific firewall as I'm not able to find these users on any firewall or panorama. If I add the user by pasting in the distinguished name in the security policy rule, it finds the user, but that is tedious 

1 accepted solution

Accepted Solutions

@MikeC,

You said this was happening across multiple firewalls and your panorama instance right? So if it's not tied to a single device then it would appear far more likely it could potentially be an issue with how your pulling the group mapping. 

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

@MikeC,

Does the user include any sort of special characters or anything if it's the same users that are breaking? 

Two of the users have periods (.) in their display name, but I have other users with this as well.   Another user that doesn't show up is a new user, standard, nothing special about it.   Seems to be a new issue because a new user that was created in the middle of the week shows up.

 

 

@MikeC,

You said this was happening across multiple firewalls and your panorama instance right? So if it's not tied to a single device then it would appear far more likely it could potentially be an issue with how your pulling the group mapping. 

@BPry 

 

Correct, multiple firewalls/panorama.  I originally thought it was group mapping, since I do a group include list and these users are not part of any of those groups.  What threw me off is, other similar users do show up and they are not part of any of the groups that I include in the group mapping

 

That indeed was the issue though. Very weird that some of the other accounts that are not part of the group mapping were showing up.  Thanks !

  • 1 accepted solution
  • 4079 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!