User-ID domain-map

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

User-ID domain-map

L2 Linker

Hi guys.

 

I have a problem with a user-id setup in a large multi domain envoirment. User-ID agentd are working fine, but the user did not match against the group mapping. It looks like we have a problem with the domain map. The command debug user-id dump domain-map delivers only a empty result. We setup the group maping against the Global Catalog of the root domain.

Does anyone know which attribute Palo Alto Networks read out of the AD for the domain-map? Maybe there is an issue withe the AD.

 

Best regards, Markus

8 REPLIES 8

Hi pakumar.

 

I know all these documents and I configured it as usual (and as described in the documents). But without success. I think my problem is the domain-map, because it should not be empty.

 

Best regards, Markus

Have you added group mapping under user-identification?

Yes, of course.

Hi. Just to be clear, I setup user-id, also in large envoirments, several times successful. But this time I have problems with the group mapping respectively the domain-map. So it would be interesting if anyone know which AD attribute or value Palo Alto Network use as domain-map.

 

Thank you and best regards, Markus

Okay try one more think change the domain name to netbios-name and test.

Hi. I tried that allready, without success.

L4 Transporter

Hi Markus,

 

Can you try this:

 

1. Modify the LDAP server profile to use port 636 for the connection to the GC.

2. Create a new group mapping using this LDAP profile.

3. Use one group from the group list pulled from the server and put it in include list and commit the changes.

 

See if it helps. Else I would suggest to contact support.

 

Regards,

Abhishek

  • 4640 Views
  • 8 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!