PA dont recognise the groups for one user

Announcements

ATTENTION Customers, All Partners and Employees: The Customer Support Portal (CSP) will be undergoing maintenance and unavailable on Saturday, November 7, 2020, from 11 am to 11 pm PST. Please read our blog for more information.

Reply
Highlighted
L4 Transporter

PA dont recognise the groups for one user

Hi,

I just upgraded to 5.0.8 and im having a problem with one user. I have a user who is not being assigned to his groups.

This user (explotacio) belongs to 3 groups in the Active directory but Palo Alto cant assign to these groups. I have clear the user-cache and it still happening.

telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.0.49

IP address:  10.1.0.49 (vsys1)

User:        obalat\explotacio

From:        UIA

Idle Timeout: 1038s

Max. TTL:    1038s

Groups that the user belongs to (used in policy)





thanks a lot

Highlighted
L6 Presenter

Have you tried to refresh group mappings ?

debug user-id reset group-mapping all

debug user-id refresh group-mapping all

Highlighted
L6 Presenter

is the user in the group created? confirm w/ following command.

admin@TDC-P-FW01> show user group name

  "cn=domain admins,cn=users,dc=pantac2003,dc=com"   cn=domain admins,cn=users,dc=pantac2003,dc=com

  "pantac2003\domain admins"                         pantac2003\domain admins

  <value>                                            Show group's members

admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"

short name:  pantac2003\domain admins

source type: ldap

source:      test

[1     ] pantac2003\admin

[2     ] pantac2003\administrator

[3     ] pantac2003\xxxx

[4     ] pantac2003\xxxx

[5     ] pantac2003\xxxx

[6     ] pantac2003\xxxx

[7     ] pantac2003\xxxx

[8     ] pantac2003\xxxxt

[9     ] pantac2003\xxxx

[10    ] pantac2003\pancpe1

[11    ] pantac2003\pan

[12    ] pantac2003\pnguyen

[13    ] pantac2003\xxx

[14    ] pantac2003\xxxx

[15    ] pantac2003\ro-admin

[16    ] pantac2003\test_user

[17    ] pantac2003\testtest1

[18    ] pantac2003\uiatest

[19    ] pantac2003\uidagent

[20    ] pantac2003\usert1

[21    ] pantac2003\userid

Highlighted
L4 Transporter

From which version do you upgrade?

I'm on 5.0.7 and I have the same situation, gorps are empty - I try it with 3 different AD users.

Highlighted
L4 Transporter

Does any change in the AD is reflecting on the PA? Like if you add a new user to a different group, does that change reflects on the PA. Just to make sure that the PA is at fault you can use a softera ldap browser to confirm.

Thanks,


Syed R Hasnain

Highlighted
L4 Transporter

Is the device successfully connected to the ldap server? Check the following information for the user-group mapping info on the firewall -

>show user group-mapping state all //will show the connection status and retrieved groups.

>show user user-IDs match-user <username> will show you the groups the user is mapped to.

The ouput of "> show user ip-user-mapping ip 10.1.0.49" will not return any groups if the user's groups are not being used in a policy.

-Groups that the user belongs to (used in policy)

Thanks,

Aditi

Highlighted
L4 Transporter
Highlighted
L4 Transporter

Its weird because i cant see any groups in ip-user-mapping but the i have checked the monitor log for this source ip 10.1.12.46 are being applied correctly......

telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.12.46

IP address:  10.1.12.46 (vsys1)

User:        oalgt\explotacio

From:        UIA

Idle Timeout: 1068s

Max. TTL:    1068s

Groups that the user belongs to (used in policy)

telindus@fw1orgt(active)>

Highlighted
L6 Presenter

can you at least provide us output for following command?

admin@TDC-P-FW01> show user group name

  "cn=domain admins,cn=users,dc=pantac2003,dc=com"   cn=domain admins,cn=users,dc=pantac2003,dc=com

  "pantac2003\domain admins"                         pantac2003\domain admins

  <value>                                            Show group's members

admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"

short name:  pantac2003\domain admins

source type: ldap

source:      test

Highlighted
L4 Transporter

short name:  oalgt\domain admins

source type: ha

source:      UIA

[1     ] oalgt\adcsvc

[2     ] oalgt\administrator

[3     ] oalgt\clustsvc

[4     ] oalgt\distribuciosms

[5     ] oalgt\dxadmin

[6     ] oalgt\emailxadm

[7     ] oalgt\scomadm

[8     ] oalgt\smsservice

[9     ] oalgt\sqlservice

[10    ] oalgt\vdiadmin

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!