PA dont recognise the groups for one user

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PA dont recognise the groups for one user

L4 Transporter

Hi,

I just upgraded to 5.0.8 and im having a problem with one user. I have a user who is not being assigned to his groups.

This user (explotacio) belongs to 3 groups in the Active directory but Palo Alto cant assign to these groups. I have clear the user-cache and it still happening.

telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.0.49

IP address:  10.1.0.49 (vsys1)

User:        obalat\explotacio

From:        UIA

Idle Timeout: 1038s

Max. TTL:    1038s

Groups that the user belongs to (used in policy)





thanks a lot

13 REPLIES 13

L4 Transporter

Is the device successfully connected to the ldap server? Check the following information for the user-group mapping info on the firewall -

>show user group-mapping state all //will show the connection status and retrieved groups.

>show user user-IDs match-user <username> will show you the groups the user is mapped to.

The ouput of "> show user ip-user-mapping ip 10.1.0.49" will not return any groups if the user's groups are not being used in a policy.

-Groups that the user belongs to (used in policy)

Thanks,

Aditi

L4 Transporter

Its weird because i cant see any groups in ip-user-mapping but the i have checked the monitor log for this source ip 10.1.12.46 are being applied correctly......

telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.12.46

IP address:  10.1.12.46 (vsys1)

User:        oalgt\explotacio

From:        UIA

Idle Timeout: 1068s

Max. TTL:    1068s

Groups that the user belongs to (used in policy)

telindus@fw1orgt(active)>

can you at least provide us output for following command?

admin@TDC-P-FW01> show user group name

  "cn=domain admins,cn=users,dc=pantac2003,dc=com"   cn=domain admins,cn=users,dc=pantac2003,dc=com

  "pantac2003\domain admins"                         pantac2003\domain admins

  <value>                                            Show group's members

admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"

short name:  pantac2003\domain admins

source type: ldap

source:      test

L4 Transporter

short name:  oalgt\domain admins

source type: ha

source:      UIA

[1     ] oalgt\adcsvc

[2     ] oalgt\administrator

[3     ] oalgt\clustsvc

[4     ] oalgt\distribuciosms

[5     ] oalgt\dxadmin

[6     ] oalgt\emailxadm

[7     ] oalgt\scomadm

[8     ] oalgt\smsservice

[9     ] oalgt\sqlservice

[10    ] oalgt\vdiadmin

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!