I have a User-Id configuration that has been working successfully for 6 months. I went to add a new group to the group include list, and the syntax that was written from Panorama had JUST the group name in this form :domain\group_name. The working groups as listed by running the ' show config merged | match group-include-list' all have a syntax similar to this: [cn=group_name, ou=users and groups, ou=yyy, dc=my_domain, dc=com] etc etc . the FW does not recognize the new group, and cannot retrieve any of the users, so it is non-functional. the previously working groups still work.
FYI: the groups show up correctly when I browse the dialog in Panorama - but none of them, even the working ones, display the cn-ou-dc parameters.
Panorama 9.1.12-h3
Pa-VM100 9.1.0-h3
... View more