- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-23-2021 10:06 AM
How often the Palo Alto LDAP group members get sync if membership changes?
If I add few more users into the group in LDAP after two weeks, it is configured on PA to block the sites, will it sync with LDAP groups?
08-24-2021 12:44 AM
Hi @ksingh1980 ,
If I understand your question correctly you are asking about the "Update Interval" for the Group Mapping, correct?
Interval depends on what you have configured - https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/user-identification/device-us...
If I recall correctly the default value is one hour (3600sec). This means that by default every hour FW will generate LDAP query to get user groups from the Active Directory.
If you add user to group you need to wait for that interval for the firewall to get the update. You can configure short interval, or you can manually force the firewall to sync the user groups, right now:
> debug user-id refresh group-mapping
08-24-2021 08:57 AM
Hello again
The interval for LDAP updates is 60 secs.. vs 60 minutes... as shown in the UserID group mapping area.
08-24-2021 02:57 PM
Right, what @aleksandar.astardzhiev correctly pointed out is that by default the Update Interval for group-mapping is set to 3600 seconds which is 60 minutes. While you absolutely can set it up to update every 60 seconds, by default the firewall is only updating group membership every 3600 seconds.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!