- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
04-02-2019 09:00 PM
Under group mappings of LDAP i have so many AD groups.
But when i run below command
show user group list
Total: 1
1* : Custom Group
IT does not show me any group names from AD?
what is the reason for that?
Also what is difference between Custom group and AD groups in LDAP?
04-03-2019 06:15 AM
do you have the correct setting in device/user identification/group mapping settings/server profile/group objects/object class
this needs to set to group. if set to user it will not show in cli
AD groups are all users with the group attribute of "member"
custom groups are defined from an attribute of your choice, in affect... a custom group...
04-03-2019 06:54 AM
I have same settings as you have shown
04-03-2019 07:10 AM
and are your groups listed in "included groups" as below
04-03-2019 07:12 AM
yes i have as you mentioned.
04-03-2019 07:29 AM
try...
show user group-mapping state all
can you see a line with "proxy state"
if you can then go to user-id agents and remove "use as ldap proxy"
04-03-2019 08:06 AM
no i do not see line with proxy state
04-03-2019 08:10 AM
are you running multi VSYS?
04-03-2019 08:16 AM
Not running multivsys
04-03-2019 08:24 AM - edited 04-03-2019 08:33 AM
show user group-mapping statistics
how many groups are numbered here?
do you use policies based on group mappings and do they work?
04-03-2019 08:29 AM - edited 04-03-2019 08:35 AM
04-03-2019 08:48 AM
show user group-mapping statistics
Name Vsys Groups Last-Action(secs) Next-Action(secs)
---------------------------------------------------------------------------
Group_Mapping_1 vsys1 11 2587 secs ago(took 0 secs) In 1013 secs
Group_Mapping_2 vsys1 8 2590 secs ago(took 0 secs) In 1010 secs
yes i use group mapping in policies and they work
04-03-2019 08:54 AM
Added
04-03-2019 09:23 AM
in your screen shot i cannot see the OU for any of the groups.
could you find one of the groups in the available list and make sure it has no special characters in the OU. as below.
if my OU was called developer&objects it would not show in CLI.
04-03-2019 09:24 AM
and i may have mentioned this before but just check your user ID agent settings and make sure none of them have a tick in "use as LDAP proxy".
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!