- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-07-2013 06:40 AM
Hi,
I just upgraded to 5.0.8 and im having a problem with one user. I have a user who is not being assigned to his groups.
This user (explotacio) belongs to 3 groups in the Active directory but Palo Alto cant assign to these groups. I have clear the user-cache and it still happening.
telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.0.49
IP address: 10.1.0.49 (vsys1)
User: obalat\explotacio
From: UIA
Idle Timeout: 1038s
Max. TTL: 1038s
Groups that the user belongs to (used in policy)
thanks a lot
10-07-2013 07:22 AM
is the user in the group created? confirm w/ following command.
admin@TDC-P-FW01> show user group name
"cn=domain admins,cn=users,dc=pantac2003,dc=com" cn=domain admins,cn=users,dc=pantac2003,dc=com
"pantac2003\domain admins" pantac2003\domain admins
<value> Show group's members
admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"
short name: pantac2003\domain admins
source type: ldap
source: test
[1 ] pantac2003\admin
[2 ] pantac2003\administrator
[3 ] pantac2003\xxxx
[4 ] pantac2003\xxxx
[5 ] pantac2003\xxxx
[6 ] pantac2003\xxxx
[7 ] pantac2003\xxxx
[8 ] pantac2003\xxxxt
[9 ] pantac2003\xxxx
[10 ] pantac2003\pancpe1
[11 ] pantac2003\pan
[12 ] pantac2003\pnguyen
[13 ] pantac2003\xxx
[14 ] pantac2003\xxxx
[15 ] pantac2003\ro-admin
[16 ] pantac2003\test_user
[17 ] pantac2003\testtest1
[18 ] pantac2003\uiatest
[19 ] pantac2003\uidagent
[20 ] pantac2003\usert1
[21 ] pantac2003\userid
10-07-2013 07:56 AM
Does any change in the AD is reflecting on the PA? Like if you add a new user to a different group, does that change reflects on the PA. Just to make sure that the PA is at fault you can use a softera ldap browser to confirm.
Thanks,
Syed R Hasnain
10-07-2013 09:39 AM
Is the device successfully connected to the ldap server? Check the following information for the user-group mapping info on the firewall -
>show user group-mapping state all //will show the connection status and retrieved groups.
>show user user-IDs match-user <username> will show you the groups the user is mapped to.
The ouput of "> show user ip-user-mapping ip 10.1.0.49" will not return any groups if the user's groups are not being used in a policy.
-Groups that the user belongs to (used in policy)
Thanks,
Aditi
10-08-2013 06:37 AM
Its weird because i cant see any groups in ip-user-mapping but the i have checked the monitor log for this source ip 10.1.12.46 are being applied correctly......
telindus@fw1orgt(active)> show user ip-user-mapping ip 10.1.12.46
IP address: 10.1.12.46 (vsys1)
User: oalgt\explotacio
From: UIA
Idle Timeout: 1068s
Max. TTL: 1068s
Groups that the user belongs to (used in policy)
telindus@fw1orgt(active)>
10-08-2013 07:19 AM
can you at least provide us output for following command?
admin@TDC-P-FW01> show user group name
"cn=domain admins,cn=users,dc=pantac2003,dc=com" cn=domain admins,cn=users,dc=pantac2003,dc=com
"pantac2003\domain admins" pantac2003\domain admins
<value> Show group's members
admin@TDC-P-FW01> show user group name "cn=domain admins,cn=users,dc=pantac2003,dc=com"
short name: pantac2003\domain admins
source type: ldap
source: test
10-08-2013 08:53 AM
short name: oalgt\domain admins
source type: ha
source: UIA
[1 ] oalgt\adcsvc
[2 ] oalgt\administrator
[3 ] oalgt\clustsvc
[4 ] oalgt\distribuciosms
[5 ] oalgt\dxadmin
[6 ] oalgt\emailxadm
[7 ] oalgt\scomadm
[8 ] oalgt\smsservice
[9 ] oalgt\sqlservice
[10 ] oalgt\vdiadmin
10-08-2013 08:53 AM
what do you see with that???
10-08-2013 09:00 AM
I assume you are using a LDAP server profile to pull the groups on the PA and also user ID agent for ip-user mapping. On the User ID agent setting on the PA do you have "use as ldap proxy" enabled? If yes can you disable it and commit on the PA.
10-08-2013 09:01 AM
Also Can you paste the output for this commands
show user group-mapping state all
show user group-mapping statistics
10-08-2013 09:14 AM
I dont have LDAP Proxy enabled.
telindus@fw1orgt(active)> show user group-mapping state all
Group Mapping(vsys1, type: other): UIA
Bind DN : cn=explotacio,ou=Noestandard,ou=ORGTusers,dc=orgt,dc=ad,dc=diba,dc=es
Base : dc=orgt,dc=ad,dc=diba,dc=es
Group Filter: (None)
User Filter: (None)
Servers : configured 3 servers
10.1.1.8(636)
Last Action Time: 599 secs ago(took 2 secs)
Next Action Time: In 3001 secs
10.1.1.249(636)
10.1.1.16(636)
Number of Groups: 594
-----------------------------------------------------------------------
telindus@fw1orgt(active)> show user group-mapping statistics
Name Vsys Groups Last-Action(secs) Next-Action(secs)
---------------------------------------------------------------------------
UIA vsys1 594 627 secs ago(took 2 secs) In 2973 secs
telindus@fw1orgt(active)> show user group-mapping statistics
Name Vsys Groups Last-Action(secs) Next-Action(secs)
---------------------------------------------------------------------------
UIA vsys1 594 632 secs ago(took 2 secs) In 2968 secs
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!