Table of Contents
< All Topics
Print

【NGAF】Policy based on User/Group not working

Issue Description

User configured SSO authentication, users are authenticated as SSO users but the application control based on the User/Group not working.


Error/Warning Information

file

Handling Process

  1. Check on Authentication Status, there is a user authenticated on the corresponding group.

  2. Try to change the network object to IP group, found that the policy got hit count.

  3. Change back the Src Address to User/Group, the policy doesn’t have a hit count.

  4. Check the online user appear in the Local Users under the corresponding group.

  5. Check the authentication Zone, found that the zone is None
    file

  6. Change the Zone to LAN zone, after that the policy start to have hit count.

Root Cause

The Authentication Zone is not selected.

Solution

On Authentication Zone, select the LAN user zone on