Policy based on User/Group not working

|
  • 165
  • 0

Issue Description

User configured SSO authentication, users are authenticated as SSO users but the application control based on the User/Group not working.

Error/Warning Information

Handling Process

1. Check on Authentication Status, there is a user authenticated on the corresponding group.
2. Try to change the network object to IP group, found that the policy got hit count.
3. Change back the Src Address to User/Group, the policy doesn't have a hit count.
4. Check the online user appear in the Local Users under the corresponding group.
5. Check the authentication Zone, found that the zone is None
6. Change the Zone to LAN zone, after that the policy start to have hit count.

Root Cause

The Authentication Zone is not selected.

Solution

On Authentication Zone, select the LAN user zone on

414086396d8be0331b.png (65.31 KB, Downloads: 0)

414086396d8be0331b.png

764586396d90fe0eef.png (95.64 KB, Downloads: 0)

764586396d90fe0eef.png

728776396d924166ce.png (94.87 KB, Downloads: 0)

728776396d924166ce.png

I want to write a case
Doc ID: 7802
Author: KY
Updated: 2022-12-12 15:42
Version: