- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-22-2016 01:18 AM
Hi,
I try to test ssl forward proxy decryption. It works fine if I use IP address as a source but if I use Users(domain) as a source it doesn't work. I can't use IP's for testing because our IP's floating. What I need to check in configuration?
Toni
06-23-2016 03:35 AM
It seems the user to group mapping is not happening correctly. See this command for one ip
show user ip-user-mapping ip x.x.x.x
See if user is showing correctly
See also associated groups are showing correctly
If not add group mapping under Device-> user identification-> group mapping
06-22-2016 01:45 AM
Is user identified properly and does show up on #show user ip-user-mapping all?
06-22-2016 02:33 AM
please take a look through this article to make sure UserID is set up properly: Getting Started: User-ID
06-22-2016 02:38 AM - edited 06-22-2016 02:44 AM
Yep. User-ID works fine but user based decryption not.
06-22-2016 05:07 AM
That's odd. We've been using TLS decryption for quite a while based on Active Directory group membership. It works fine here (other than the fact that downloads over decrypted TLS sessions are incredibly slow).
06-22-2016 05:33 AM
Thanks for information. At least I know now that it could work.
06-22-2016 07:07 AM
Which version of PANOS are you running on?
06-22-2016 07:54 AM
I am running 7.0.5-h2, use user ID and do user based decryption as part of a pilot for decryption right now. No issues here.
06-23-2016 12:25 AM
Hello,
Our current version is 7.0.5-h2.
How you configure policy. Source address any and user domain\user ?
br
Toni
06-23-2016 03:35 AM
It seems the user to group mapping is not happening correctly. See this command for one ip
show user ip-user-mapping ip x.x.x.x
See if user is showing correctly
See also associated groups are showing correctly
If not add group mapping under Device-> user identification-> group mapping
06-23-2016 03:59 AM
Hi,
show user ip-user-mapping ip x.x.x.x --> I can see my username correctly. But I can't see any groups associated --> Groups that the user belongs to (used in policy). This is empty.
I can see my username in group if --> show user group name "CN=XXXXXXXXX,OU=XXXXXXXX,OU=XXXX,DC=XX,DC=XXXXXX,DC=XXXX,DC=XXX"
Toni
06-23-2016 04:30 AM - edited 06-23-2016 04:31 AM
Sorry that was used in policy so that's also ok.
06-23-2016 04:36 AM
Hello, I just found solution. It was in group mapping settings. User Domain was missing above Group Objects.
Thank you all for help. You put me to right direction!
br
Toni
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!