group mapping

Reply
Highlighted
L6 Presenter

group mapping

When we add a group from Active directory gorup list from Group mapping on Panos to right side of that window; it should come to the policy users tab.But sometimes it does not come for a time.Is there a way to refresh that or what is refresh  time for that, can we change it ?

Highlighted
L3 Networker

Re: group mapping

Hi Bulent,

When you log in to the CLI and enter the show user group-mapping-service status command, what do you see?

A.

(Now shamelessly accepting the next 49 friend requests.)

Highlighted
L6 Presenter

Re: group mapping

I see query number 2

and also local :2

but at policy ı see 1 group only.

I first saw this on customer site and tried on my lab and see the same thing.Both panos 5.0.2

Highlighted
L6 Presenter

Re: group mapping

After some while(about 2 minutes) now it came 2 groups.

What affects this time ?I have to know that.

Highlighted
L3 Networker

Re: group mapping

Device > User Identification > Group Mapping Settings > Choose the group mapping you've created.

There you will see the Update Interval. Adjust to your needs.

A.

(Now shamelessly accepting the following 15 friend requests.)

Highlighted
L6 Presenter

Re: group mapping

I am choosing from there.But it comes late to policy.that is the problem.if interval is empty isn't it 60 seconds by default ?

Highlighted
L3 Networker

Re: group mapping

No, the default interval when empty is 600 seconds (10 minutes).

Highlighted
L6 Presenter

Re: group mapping

if the default is 600 seconds why do I see sometime in 2 minutes ?

Highlighted
L5 Sessionator

Re: group mapping

The default update timer on group information, if left blank, is 600 seconds. You can change this interval by filling in a number between 60 and 86400 seconds

You can refresh the user-group-mapping by CLI commands :

> debug user-id refresh group-mapping all    ..... This command will fetch the only delta values or the difference.

> debug user-id reset group-mapping all     ...... This command will fetch the entire group mappings once again.

HTH..!


-AMEYA

Highlighted
L6 Presenter

Re: group mapping

we tried these commands yesterday but it did not work.

Thanks.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!