Command user group name not working

Reply
Highlighted
L4 Transporter

Command user group name not working

Hi,

 

We just check that the command:  show user group name 'cn=......' has this output: 

user group xxxxx does not exist or does not have members. All config is OK. 

 

If we run "show user group list", i can see al the groups, but filtering by one of them shows:

user group xxxxx does not exist or does not have members

 

show user ip-user-mapping all ---> OK

show user user-ids match-user xxxx ---> OK

 

 

Why is not showing users in groups?

Highlighted
Cyber Elite

@jesuscano,

Is the group in your group-include-list? My first thought would be that you are trying to look at group membership for a group that the firewall isn't actively pulling, thus it doesn't know/care if anyone is in that group. Trying running the same command on something that you are actively included in your group-include-list and you should have all members listed. 

Highlighted
L4 Transporter

Yes, group is included in the list. We tried to put all in list, just in case, but the result is the same. Its weird...

 

Its happening with all the groups in "show user group list". 

Highlighted
Cyber Elite

@jesuscano,

Hmm that's really odd. I might try restarting the management plane just to see if that resolves the issue, otherwise I would open a support case about it.

Highlighted
L7 Applicator

Probably teaching you to suck eggs here but have you copied and paste group name as syntax is essential here..

 

also.. do you have any special characters in the group name such as ampersand or comma...

 

do you get the expected output from  show user group-mapping state all.    Return the expected output.

 

do you only have permissions to see the groups but not the members.

 

is your group mapping correct....   ie- object for both group objects and user objects.

Highlighted
L4 Transporter

Its happening for all groups using "show user group name xx" comand.

 

We have vsys and we also tried go in the vsys to tun the command.

 

The rest of the mapping commands are working fine.

 

About user permission, customer has more FWs with this bind ldap user and in the rest of fws are working fine this command.

Highlighted
L0 Member

Did you ever figure this out as we seem to have the same issue and its affecting our VPN groups as its apparently the user isn't in the allowed auth list even though if you look at the user in the cli it will list the group but listing the group members in the cli comes up with a "user group does not exist or does not have members"

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!