- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-17-2011 11:40 PM
Our PA 4.1 has problems mapping entries received from user-ID agent and LDAP queries.
show user ip-user-mapping command produces following output:
192.168.1.1 AD grybai\vltr12345678
Here grybai is our NetBIOS domain name for domain and vltr12345678 is sAMAccountName attribute of user object in LDAP.
However command show user user-IDs (which shows information received by PA from LDAP queries) for the same user shows:
tadas.blinda@grybaiagrupe.eu vsys1 cn=b8710 users,ou=email,ou=groups,dc=corp,dc=grybaigroup,dc=eu
where tadas.blinda@grybaiagrupe.eu is userPrincipalName attribute for the same user.
During policy configuration PA web interface gives list of users in tadas.blinda@grybaiagrupe.eu , however such policy doesn't match traffic for that user. Policy with group also doesn't match traffic for that user.
If add policy with grybai\vltr12345678 user (I have to manually type user name during policy configuration), it matches traffic for that user.
LDAP server is configured as type active-directory, under "Group mapping settings" username field is configured as sAMAccountName (default). Tried to change that value with no lock.
Any ideas how to fix it?
11-19-2011 10:08 PM
For the group errors;
In the LDAP config, under active directory name, make sure this setting is in NETBIOS format not DNS name.
eg DOMAINNAME and not domainname.com
11-21-2011 07:54 AM
In the User-ID_Upgrade_4.1 it is quite clearly noted not configure any domain unless device is working in multidomain environment, so we don't configured any. Before posting this post I tried to configure both netbios and dns domains without any luck.
06-20-2018 05:49 AM
Did You resolve this issue? I have same problem..
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!