When we add a group from Active directory gorup list from Group mapping on Panos to right side of that window; it should come to the policy users tab.But sometimes it does not come for a time.Is there a way to refresh that or what is refresh time for that, can we change it ?
When you log in to the CLI and enter the show user group-mapping-service status command, what do you see?
(Now shamelessly accepting the next 49 friend requests.)
I see query number 2
and also local :2
but at policy ı see 1 group only.
I first saw this on customer site and tried on my lab and see the same thing.Both panos 5.0.2
Device > User Identification > Group Mapping Settings > Choose the group mapping you've created.
There you will see the Update Interval. Adjust to your needs.
(Now shamelessly accepting the following 15 friend requests.)
The default update timer on group information, if left blank, is 600 seconds. You can change this interval by filling in a number between 60 and 86400 seconds
You can refresh the user-group-mapping by CLI commands :
> debug user-id refresh group-mapping all ..... This command will fetch the only delta values or the difference.
> debug user-id reset group-mapping all ...... This command will fetch the entire group mappings once again.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!
The Live Community thanks you for your participation!