How often the Palo Alto LDAP group members get sync if membership changes ?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

How often the Palo Alto LDAP group members get sync if membership changes ?

L0 Member

How often the Palo Alto LDAP group members get sync if membership changes?

 

If I add few more users into the group in LDAP after two weeks, it is configured on PA to block the sites, will it sync with LDAP groups?

3 REPLIES 3

Hi @ksingh1980 ,

If I understand your question correctly you are asking about the "Update Interval" for the Group Mapping, correct?

Interval depends on what you have configured - https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/user-identification/device-us...

If I recall correctly the default value is one hour (3600sec). This means that by default every hour FW will generate LDAP query to get user groups from the Active Directory.

If you add user to group you need to wait for that interval for the firewall to get the update. You can configure short interval, or you can manually force the firewall to sync the user groups, right now:

> debug user-id refresh group-mapping

 

Hello again

 

The interval for LDAP updates is 60 secs.. vs 60 minutes... as shown in the UserID group mapping area.

 

 

SteveCantwell_0-1629820553327.png

 

SteveCantwell_1-1629820611883.png

 

Help the community: Like helpful comments and mark solutions

Cyber Elite
Cyber Elite

@S.Cantwell,

Right, what @aleksandar.astardzhiev correctly pointed out is that by default the Update Interval for group-mapping is set to 3600 seconds which is 60 minutes. While you absolutely can set it up to update every 60 seconds, by default the firewall is only updating group membership every 3600 seconds. 

  • 7409 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!