I opened a case in this regard, but in the meantime I would like to know if anyone has the same problem as me. -I'm using version 4.1.8 of PA, the PA-2050 appliance. -User ID agent v.4.1.4.3 is use for authen users. - ad windows, on server 2008, for LDAP. I regularly lose the link between a user and the group associated with that user. Result: I have several rules that give special access, for example, social networks or personal web storage. At the beginning, when creating the rule, it works, but after about a week they stop working. The user is authenticated, in the "MONITOR" I can see the user in the USER column. But I still see a bad rule that is applied to that person. This is the last rule is applied, which provides access to the Internet by default. When this happens, here's what I see in the CLI: - Show user group name domain \ group-1 [1] domain \ user01 [2] domain \ user02 Then I demand groups that are associated with the user "user02" and I get no group. show user-IDs match user-user domain \ user02: User Name VSYS Groups -------------------------------------------------- ---------------- When it works, the CLI command "show user-IDs match user-user" returns me the right groups associated with the user.
... View more