LDAP groups not populating correctly

Showing results for 
Show  only  | Search instead for 
Did you mean: 

LDAP groups not populating correctly

L3 Networker

PA220, PANOS 8.1.1

Working on setting up GlobalProtect using AD/LDAP auth and groups to define access. 
I have userconfigs setup by AD Group and the log is "matching config not found" 
On digging into it some more, it appears that the user, in the PA, doesn't have the appropriate groups attached. Despite that they do in AD. 

AD Group has four members. Three of the members show up in the PA. The fourth does not. 
show user user-ids match-user domain\ProblemUser  returns an empty table. While the other three users in the group return complete information as expected. 
Account is functional and has full access to what all it's supposed to from the AD side of things. 

I've done a debug user-id reset group-mapping all and I'm  still having the same issues. 

Where should I start troubleshooting from here? 


Okay, I follow you now. 

I just switched to my domain admin and now the group membership shows correctly. 

Now I'll go talk to the AD admin and find out what needs to happen to make this work. 

Thanks for your input!
I'll update if/when I find the cure. 

Nice one, sorry for the confusion....

After banging our head on it a lot lately, we finally found that adding the Domain Users group to the GroupMapping resolved the issue. 

Unclear why this is the case, but maybe it'll help someone else in the future. 

edited to improve clarity



So you really had to add a single user to the group mapping? ... sounds like a bug to me ...

You could try to update to 8.1.2 ... maybe your lucky and then it "magically" works.

@vsys_remo No, I had to add the group Domain Users to the Group Mapping to get the details on the users to show correctly. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!