<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP Members in  group Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-members-in-group-issue/m-p/523762#M108437</link>
    <description>&lt;P&gt;Issues with Members in a group and a security policy&lt;/P&gt;
&lt;P&gt;- pa 850/9.15 os level&lt;/P&gt;
&lt;P&gt;- I use ldap to sync with AD , I merged the groups I need in the include group option&lt;/P&gt;
&lt;P&gt;- I see all the groups in cli by using show groups&lt;/P&gt;
&lt;P&gt;- I can also list members in the group from cli ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- I use Kerbose to sycn user id's and they also show up in the userid /monitor..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- If I put in a security policy by an AD group name as parameter to apply to a group "A", it fails to execute and drops through to a lower rule.&lt;/P&gt;
&lt;P&gt;- If I put a user who exists in group "A" in the rule same rule , the rule works for the user only,..,&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;- In essence, the firewall knows about the groups and the users, but the security rule it doesn't seem to understand about that user inside the group&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- When I use the cli to list the user group A , it lists of the members.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 10 Dec 2022 16:10:14 GMT</pubDate>
    <dc:creator>SteveHolzman</dc:creator>
    <dc:date>2022-12-10T16:10:14Z</dc:date>
    <item>
      <title>LDAP Members in  group Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-members-in-group-issue/m-p/523762#M108437</link>
      <description>&lt;P&gt;Issues with Members in a group and a security policy&lt;/P&gt;
&lt;P&gt;- pa 850/9.15 os level&lt;/P&gt;
&lt;P&gt;- I use ldap to sync with AD , I merged the groups I need in the include group option&lt;/P&gt;
&lt;P&gt;- I see all the groups in cli by using show groups&lt;/P&gt;
&lt;P&gt;- I can also list members in the group from cli ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- I use Kerbose to sycn user id's and they also show up in the userid /monitor..&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- If I put in a security policy by an AD group name as parameter to apply to a group "A", it fails to execute and drops through to a lower rule.&lt;/P&gt;
&lt;P&gt;- If I put a user who exists in group "A" in the rule same rule , the rule works for the user only,..,&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;- In essence, the firewall knows about the groups and the users, but the security rule it doesn't seem to understand about that user inside the group&amp;nbsp;&lt;/P&gt;
&lt;P&gt;- When I use the cli to list the user group A , it lists of the members.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 16:10:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-members-in-group-issue/m-p/523762#M108437</guid>
      <dc:creator>SteveHolzman</dc:creator>
      <dc:date>2022-12-10T16:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Members in  group Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-members-in-group-issue/m-p/523763#M108438</link>
      <description>&lt;P&gt;It seems as if I solved my own laziness..&lt;/P&gt;
&lt;P&gt;I originally cloned an existing rule, and modified it..&lt;/P&gt;
&lt;P&gt;When I started a new&amp;nbsp; rule using the group , it now works..&lt;/P&gt;</description>
      <pubDate>Sat, 10 Dec 2022 16:17:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-members-in-group-issue/m-p/523763#M108438</guid>
      <dc:creator>SteveHolzman</dc:creator>
      <dc:date>2022-12-10T16:17:42Z</dc:date>
    </item>
  </channel>
</rss>

