Can't find user for security policy rule

Reply
Highlighted
L3 Networker

Can't find user for security policy rule

Having a bit of an issue but can't seem to pinpoint the solution..   When I go to add a security policy rule, under user, i cannot find specific users.   However, when I go to the traffic monitor tab, I can see the user mapping is working from the User-ID agent, since I can find those same users there.

 

Not tied to a specific firewall as I'm not able to find these users on any firewall or panorama. If I add the user by pasting in the distinguished name in the security policy rule, it finds the user, but that is tedious 


Accepted Solutions
Highlighted
Cyber Elite

@MikeC,

You said this was happening across multiple firewalls and your panorama instance right? So if it's not tied to a single device then it would appear far more likely it could potentially be an issue with how your pulling the group mapping. 

View solution in original post


All Replies
Highlighted
Cyber Elite

@MikeC,

Does the user include any sort of special characters or anything if it's the same users that are breaking? 

Highlighted
L3 Networker

Two of the users have periods (.) in their display name, but I have other users with this as well.   Another user that doesn't show up is a new user, standard, nothing special about it.   Seems to be a new issue because a new user that was created in the middle of the week shows up.

 

 

Highlighted
Cyber Elite

@MikeC,

You said this was happening across multiple firewalls and your panorama instance right? So if it's not tied to a single device then it would appear far more likely it could potentially be an issue with how your pulling the group mapping. 

View solution in original post

Highlighted
L3 Networker

@BPry 

 

Correct, multiple firewalls/panorama.  I originally thought it was group mapping, since I do a group include list and these users are not part of any of those groups.  What threw me off is, other similar users do show up and they are not part of any of the groups that I include in the group mapping

 

That indeed was the issue though. Very weird that some of the other accounts that are not part of the group mapping were showing up.  Thanks !

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!