user-ID user mapping problems

Showing results for 
Show  only  | Search instead for 
Did you mean: 

user-ID user mapping problems

Not applicable

Our PA 4.1 has problems mapping entries received from user-ID agent and LDAP queries.

show user ip-user-mapping command produces following output: AD        grybai\vltr12345678

Here grybai is our NetBIOS domain name for domain and  vltr12345678 is sAMAccountName attribute of user object in LDAP.

However command show user user-IDs (which shows information received by PA from LDAP queries) for the same user shows:    vsys1   cn=b8710 users,ou=email,ou=groups,dc=corp,dc=grybaigroup,dc=eu

where is userPrincipalName attribute for the same user.

During policy configuration PA web interface gives list of users in , however such policy doesn't match traffic for that user. Policy with group also doesn't match traffic for that user.

If add policy with grybai\vltr12345678 user (I have to manually type user name during policy configuration), it matches traffic for that user.

LDAP server is configured as type active-directory, under "Group mapping settings" username field is configured as sAMAccountName (default). Tried to change that value with no lock.

Any ideas how to fix it?


L0 Member

For the group errors;

In the LDAP config, under active directory name, make sure this setting is in NETBIOS format not DNS name.

eg DOMAINNAME and not

In the User-ID_Upgrade_4.1 it is quite clearly noted not configure any domain unless device is working in multidomain environment, so we don't configured any. Before posting this post I tried to configure both netbios and dns domains without any luck.

Did You resolve this issue? I have same problem..

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!