- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-08-2015 12:39 PM
Hi guys.
I have a problem with a user-id setup in a large multi domain envoirment. User-ID agentd are working fine, but the user did not match against the group mapping. It looks like we have a problem with the domain map. The command debug user-id dump domain-map delivers only a empty result. We setup the group maping against the Global Catalog of the root domain.
Does anyone know which attribute Palo Alto Networks read out of the AD for the domain-map? Maybe there is an issue withe the AD.
Best regards, Markus
12-08-2015 12:48 PM - edited 12-08-2015 12:50 PM
Check these DOC's
Hope this helps.
12-08-2015 01:04 PM
Hi pakumar.
I know all these documents and I configured it as usual (and as described in the documents). But without success. I think my problem is the domain-map, because it should not be empty.
Best regards, Markus
12-08-2015 01:22 PM
Have you added group mapping under user-identification?
12-08-2015 01:29 PM
Hi. Just to be clear, I setup user-id, also in large envoirments, several times successful. But this time I have problems with the group mapping respectively the domain-map. So it would be interesting if anyone know which AD attribute or value Palo Alto Network use as domain-map.
Thank you and best regards, Markus
12-08-2015 01:32 PM
Okay try one more think change the domain name to netbios-name and test.
12-08-2015 01:33 PM
Hi. I tried that allready, without success.
12-08-2015 06:51 PM
Hi Markus,
Can you try this:
1. Modify the LDAP server profile to use port 636 for the connection to the GC.
2. Create a new group mapping using this LDAP profile.
3. Use one group from the group list pulled from the server and put it in include list and commit the changes.
See if it helps. Else I would suggest to contact support.
Regards,
Abhishek
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!