Error:
An unexpected error occurred. Please click Reload to try again.
Error:
An unexpected error occurred. Please click Reload to try again.
Traffic not matching the configured security policy with user g... - Knowledge Base - Palo Alto Networks

Traffic not matching the configured security policy with user groups

9382
Created On 04/18/21 18:04 PM - Last Modified 03/07/23 04:45 AM


Symptom


  • Security Policies with User-ID Groups not matching traffic
  • Created new Security Policy with same User-ID Group and is working


Environment


  • Prisma Access
  • User-ID based Security Policies


Cause


Group name format was incorrect as there was an added space between groups.
Working
"cn=global prod url filtering exception unrestricted,ou=security services,ou=enterprise services,dc=acme,dc=org".

Not working
"cn=global prod url filtering exception unrestricted, ou=security services, ou=enterprise services, dc=zurich,dc=com"   (unnecessary spaces)
"cn=Global prod url filtering exception unrestricted,ou=Security services,ou=Enterprise services,dc=Acme,dc=Org"    (unnecessary uppercase)


Resolution


Find the correct user-group name and configure it in the appropriate security policies. This can be done as follows -
  1. Find your group names from your LDAP Server and note them down.
  2. From PAN-OS GUI: Navigate to Device>User Identification>Group Mapping Settings
  3. Add/Edit your group > Select tab Group Include List
  4. Click Add >  Copy all your groups you plan to use in your Security Policies
  5. Click OK, then Commit and Push your changes


Additional Information


How to check user groups: https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClVcCAK

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000sY3lCAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language