PA dont recognise the groups for one user

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

PA dont recognise the groups for one user

L4 Transporter

Hi,

I just upgraded to 5.0.8 and im having a problem with one user. I have a user who is not being assigned to his groups.

This user (explotacio) belongs to 3 groups in the Active directory but Palo Alto cant assign to these groups. I have clear the user-cache and it still happening.

telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.0.49

IP address:  10.1.0.49 (vsys1)

User:        obalat\explotacio

From:        UIA

Idle Timeout: 1038s

Max. TTL:    1038s

Groups that the user belongs to (used in policy)





thanks a lot

13 REPLIES 13

L6 Presenter

Have you tried to refresh group mappings ?

debug user-id reset group-mapping all

debug user-id refresh group-mapping all

L6 Presenter

is the user in the group created? confirm w/ following command.

admin@TDC-P-FW01> show user group name

  "cn=domain admins,cn=users,dc=pantac2003,dc=com"   cn=domain admins,cn=users,dc=pantac2003,dc=com

  "pantac2003\domain admins"                         pantac2003\domain admins

  <value>                                            Show group's members

admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"

short name:  pantac2003\domain admins

source type: ldap

source:      test

[1     ] pantac2003\admin

[2     ] pantac2003\administrator

[3     ] pantac2003\xxxx

[4     ] pantac2003\xxxx

[5     ] pantac2003\xxxx

[6     ] pantac2003\xxxx

[7     ] pantac2003\xxxx

[8     ] pantac2003\xxxxt

[9     ] pantac2003\xxxx

[10    ] pantac2003\pancpe1

[11    ] pantac2003\pan

[12    ] pantac2003\pnguyen

[13    ] pantac2003\xxx

[14    ] pantac2003\xxxx

[15    ] pantac2003\ro-admin

[16    ] pantac2003\test_user

[17    ] pantac2003\testtest1

[18    ] pantac2003\uiatest

[19    ] pantac2003\uidagent

[20    ] pantac2003\usert1

[21    ] pantac2003\userid

L4 Transporter

From which version do you upgrade?

I'm on 5.0.7 and I have the same situation, gorps are empty - I try it with 3 different AD users.

Does any change in the AD is reflecting on the PA? Like if you add a new user to a different group, does that change reflects on the PA. Just to make sure that the PA is at fault you can use a softera ldap browser to confirm.

Thanks,


Syed R Hasnain

L4 Transporter

Is the device successfully connected to the ldap server? Check the following information for the user-group mapping info on the firewall -

>show user group-mapping state all //will show the connection status and retrieved groups.

>show user user-IDs match-user <username> will show you the groups the user is mapped to.

The ouput of "> show user ip-user-mapping ip 10.1.0.49" will not return any groups if the user's groups are not being used in a policy.

-Groups that the user belongs to (used in policy)

Thanks,

Aditi

L4 Transporter

Its weird because i cant see any groups in ip-user-mapping but the i have checked the monitor log for this source ip 10.1.12.46 are being applied correctly......

telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.12.46

IP address:  10.1.12.46 (vsys1)

User:        oalgt\explotacio

From:        UIA

Idle Timeout: 1068s

Max. TTL:    1068s

Groups that the user belongs to (used in policy)

telindus@fw1orgt(active)>

can you at least provide us output for following command?

admin@TDC-P-FW01> show user group name

  "cn=domain admins,cn=users,dc=pantac2003,dc=com"   cn=domain admins,cn=users,dc=pantac2003,dc=com

  "pantac2003\domain admins"                         pantac2003\domain admins

  <value>                                            Show group's members

admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"

short name:  pantac2003\domain admins

source type: ldap

source:      test

L4 Transporter

short name:  oalgt\domain admins

source type: ha

source:      UIA

[1     ] oalgt\adcsvc

[2     ] oalgt\administrator

[3     ] oalgt\clustsvc

[4     ] oalgt\distribuciosms

[5     ] oalgt\dxadmin

[6     ] oalgt\emailxadm

[7     ] oalgt\scomadm

[8     ] oalgt\smsservice

[9     ] oalgt\sqlservice

[10    ] oalgt\vdiadmin

what do you see with that???

I assume you are using a LDAP server profile to pull the groups on the PA and also user ID agent for ip-user mapping. On the User ID agent setting on the PA do you have "use as ldap proxy" enabled? If yes can you disable it and commit on the PA.

Also Can you paste the output for this commands

show user group-mapping state all

show user group-mapping statistics

L4 Transporter

I dont have LDAP Proxy enabled.

telindus@fw1orgt(active)> show user group-mapping state all

Group Mapping(vsys1, type: other): UIA

        Bind DN    : cn=explotacio,ou=Noestandard,ou=ORGTusers,dc=orgt,dc=ad,dc=diba,dc=es

        Base       : dc=orgt,dc=ad,dc=diba,dc=es

        Group Filter: (None)

        User Filter: (None)

        Servers    : configured 3 servers

                10.1.1.8(636)

                        Last Action Time: 599 secs ago(took 2 secs)

                        Next Action Time: In 3001 secs

                10.1.1.249(636)

                10.1.1.16(636)

        Number of Groups: 594

-----------------------------------------------------------------------

telindus@fw1orgt(active)> show user group-mapping statistics

Name         Vsys    Groups Last-Action(secs)                Next-Action(secs)

---------------------------------------------------------------------------

UIA          vsys1   594    627 secs ago(took 2 secs)        In 2973 secs

telindus@fw1orgt(active)> show user group-mapping statistics

Name         Vsys    Groups Last-Action(secs)                Next-Action(secs)

---------------------------------------------------------------------------

UIA          vsys1   594    632 secs ago(took 2 secs)        In 2968 secs

  • 5786 Views
  • 13 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!