<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Domain and domain name in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21378#M15594</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try using &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;IDF&lt;/SPAN&gt; as a domain in the LDAP server profile and refresh the group-mapping :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id refresh group-mapping &amp;lt;&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Jun 2013 09:53:18 GMT</pubDate>
    <dc:creator>UhMayYeah</dc:creator>
    <dc:date>2013-06-13T09:53:18Z</dc:date>
    <item>
      <title>Multiple Domain and domain name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21377#M15593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have deployed 1 cluster of PA 3020(5.0.5) and UIA on 2 servers of the domain.&lt;/P&gt;&lt;P&gt;The domain architecture is as following:&lt;/P&gt;&lt;P&gt;1 parent domain: idf.local&lt;/P&gt;&lt;P&gt;6 child domain: xx.idf.local, yy.idf.local, ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UIA works well and we have good informations on the PA with NETBIOS domaine name&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all:&lt;/P&gt;&lt;P&gt;IDF\user1&lt;/P&gt;&lt;P&gt;XX\user2&lt;/P&gt;&lt;P&gt;YY\user3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But with the group mapping, it's fqdn domain that appears.&lt;/P&gt;&lt;P&gt;show user group name "cn=ggggggg,ou=fffffffff,dc=idf,dc=local":&lt;/P&gt;&lt;P&gt;idf.local\user1&lt;/P&gt;&lt;P&gt;xx.idf.local\user2&lt;/P&gt;&lt;P&gt;yy.idf.local\user3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;LDAP server profile configuration is done with global catalog:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@XXXXXX(active)# show shared server-profile ldap profile-AD-GC&lt;/P&gt;&lt;P&gt;profile-AD-GC {&lt;/P&gt;&lt;P&gt;&amp;nbsp; server {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; gtgt50.idf.local {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 3269;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; address 192.168.1.1;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;&amp;nbsp; ldap-type active-directory;&lt;/P&gt;&lt;P&gt;&amp;nbsp; base DC=idf,DC=local;&lt;/P&gt;&lt;P&gt;&amp;nbsp; bind-dn "CN=login,......,DC=idf,DC=local";&lt;/P&gt;&lt;P&gt;&amp;nbsp; timelimit 30;&lt;/P&gt;&lt;P&gt;&amp;nbsp; bind-timelimit 30;&lt;/P&gt;&lt;P&gt;&amp;nbsp; bind-password -AQ==SdRlIx0rvZ/zcM4qhyMPexBjphE=Xce5R8I57K7Xi1MRcJdzBg==;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl yes;&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;&lt;P&gt;[edit]&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that I can't create policy based on AD group because there is a mismatch between UIA and Group Mapping information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 08:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21377#M15593</guid>
      <dc:creator>NomiosSupport</dc:creator>
      <dc:date>2013-06-13T08:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Domain and domain name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21378#M15594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try using &lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;IDF&lt;/SPAN&gt; as a domain in the LDAP server profile and refresh the group-mapping :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt; debug user-id refresh group-mapping &amp;lt;&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 09:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21378#M15594</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-06-13T09:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Domain and domain name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21379#M15595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have already tried this but it overrides all domain name:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;show user group name "cn=ggggggg,ou=fffffffff,dc=idf,dc=local":&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;IDF\user1&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;IDF\user2&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;IDF\user3&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;The problem is that user2 belongs to XX domain which is the domain child(xx.idf.local).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 15:05:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21379#M15595</guid>
      <dc:creator>NomiosSupport</dc:creator>
      <dc:date>2013-06-13T15:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Domain and domain name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21380#M15596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try creating separate LDAP Server (port 389 or 636) profiles for the parent domain and each child domain including in the configuration NetBios-style domain name and corresponding base.&lt;/P&gt;&lt;P&gt;In Group Mapping Settings create Group Mapping configuration using every LDAP Server Profile (8 in total).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps! Update if it does &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Global Catalog is used for identifying membership in Universal Groups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 10:05:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21380#M15596</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-06-14T10:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Domain and domain name</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21381#M15597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As albert_C said, create one ldap profile per server and configure "Domain" in the profile then, domain name will be re-write as you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Jun 2013 10:29:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-domain-and-domain-name/m-p/21381#M15597</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-06-14T10:29:53Z</dc:date>
    </item>
  </channel>
</rss>

