10-07-2013 06:40 AM
Hi,
I just upgraded to 5.0.8 and im having a problem with one user. I have a user who is not being assigned to his groups.
This user (explotacio) belongs to 3 groups in the Active directory but Palo Alto cant assign to these groups. I have clear the user-cache and it still happening.
telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.0.49
IP address: 10.1.0.49 (vsys1)
User: obalat\explotacio
From: UIA
Idle Timeout: 1038s
Max. TTL: 1038s
Groups that the user belongs to (used in policy)
thanks a lot
10-07-2013 09:39 AM
Is the device successfully connected to the ldap server? Check the following information for the user-group mapping info on the firewall -
>show user group-mapping state all //will show the connection status and retrieved groups.
>show user user-IDs match-user <username> will show you the groups the user is mapped to.
The ouput of "> show user ip-user-mapping ip 10.1.0.49" will not return any groups if the user's groups are not being used in a policy.
-Groups that the user belongs to (used in policy)
Thanks,
Aditi
10-08-2013 06:37 AM
Its weird because i cant see any groups in ip-user-mapping but the i have checked the monitor log for this source ip 10.1.12.46 are being applied correctly......
telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.12.46
IP address: 10.1.12.46 (vsys1)
User: oalgt\explotacio
From: UIA
Idle Timeout: 1068s
Max. TTL: 1068s
Groups that the user belongs to (used in policy)
telindus@fw1orgt(active)>
10-08-2013 07:19 AM
can you at least provide us output for following command?
admin@TDC-P-FW01> show user group name
"cn=domain admins,cn=users,dc=pantac2003,dc=com" cn=domain admins,cn=users,dc=pantac2003,dc=com
"pantac2003\domain admins" pantac2003\domain admins
<value> Show group's members
admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"
short name: pantac2003\domain admins
source type: ldap
source: test
10-08-2013 08:53 AM
short name: oalgt\domain admins
source type: ha
source: UIA
[1 ] oalgt\adcsvc
[2 ] oalgt\administrator
[3 ] oalgt\clustsvc
[4 ] oalgt\distribuciosms
[5 ] oalgt\dxadmin
[6 ] oalgt\emailxadm
[7 ] oalgt\scomadm
[8 ] oalgt\smsservice
[9 ] oalgt\sqlservice
[10 ] oalgt\vdiadmin
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!