I have a problem with a user-id setup in a large multi domain envoirment. User-ID agentd are working fine, but the user did not match against the group mapping. It looks like we have a problem with the domain map. The command debug user-id dump domain-map delivers only a empty result. We setup the group maping against the Global Catalog of the root domain.
Does anyone know which attribute Palo Alto Networks read out of the AD for the domain-map? Maybe there is an issue withe the AD.
Best regards, Markus
Check these DOC's
Hope this helps.
Hi. Just to be clear, I setup user-id, also in large envoirments, several times successful. But this time I have problems with the group mapping respectively the domain-map. So it would be interesting if anyone know which AD attribute or value Palo Alto Network use as domain-map.
Thank you and best regards, Markus
Can you try this:
1. Modify the LDAP server profile to use port 636 for the connection to the GC.
2. Create a new group mapping using this LDAP profile.
3. Use one group from the group list pulled from the server and put it in include list and commit the changes.
See if it helps. Else I would suggest to contact support.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!