<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Want to create a security policy based on domain user group. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2152#M1594</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a document that explains how to configure User-ID agent and the LDAP server group mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3120"&gt;https://live.paloaltonetworks.com/docs/DOC-3120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have all the configuration set according to the document. I would ask you to check whether the firewall is actually pulling the user-groups information. This can be verified with the command " show user group-mapping state all" . If you are able to see all the groups information in the output then the group mapping is working properly. So you might want to try using different browsers to create security rules and see if it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Sep 2012 18:17:17 GMT</pubDate>
    <dc:creator>sdurga</dc:creator>
    <dc:date>2012-09-13T18:17:17Z</dc:date>
    <item>
      <title>Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2151#M1593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, I would like to set up a security policy based on a group a user belongs to on my AD. I've set up the LDAP, and USER ID client on the server, but when I go to create the security rule, nothing shows up in the add box for the user. Even if I click the drop down, or start to type the domain/username info. I'm thinking I missed a step, or something. Can anyone recommend somethings I should check, or point me in the direction of some good documents?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 17:49:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2151#M1593</guid>
      <dc:creator>jbaublitz</dc:creator>
      <dc:date>2012-09-13T17:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2152#M1594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a document that explains how to configure User-ID agent and the LDAP server group mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3120"&gt;https://live.paloaltonetworks.com/docs/DOC-3120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have all the configuration set according to the document. I would ask you to check whether the firewall is actually pulling the user-groups information. This can be verified with the command " show user group-mapping state all" . If you are able to see all the groups information in the output then the group mapping is working properly. So you might want to try using different browsers to create security rules and see if it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 18:17:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2152#M1594</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-13T18:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2153#M1595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the firewall isn't showing User Info:&lt;/P&gt;&lt;P&gt;Verify if the Agent is&amp;nbsp; the User-Mapping :&lt;/P&gt;&lt;P&gt;CLI command to verify User-IP Mapping (Done by User-Id Agent)&lt;/P&gt;&lt;P&gt;&amp;gt;show user ip-user-mapping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see this command not showing IP-User Mapping :&lt;/P&gt;&lt;P&gt;Check if the Agent is connected also verify if you see Discovered Users on the Agent (Monitor).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer:&lt;/P&gt;&lt;P&gt;User Identification Initial Setup&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2021" data-containertype="14" data-objectid="3664" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3664"&gt;https://live.paloaltonetworks.com/docs/DOC-3664&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If IP-User Mapping is being done as expected verify LDAP config for User-Group Mapping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CLI command to verify User-Group Mapping (Done by Firewall via LDAP)&lt;/P&gt;&lt;P&gt;Enlists Users in the group (Included Groups in LDAP/All if No Included Groups configured)&lt;/P&gt;&lt;P&gt;&amp;gt;show user group name &amp;lt;value&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User Identification Tech Note PAN-OS 4.1&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" data-containerid="2021" data-containertype="14" data-objectid="3120" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3120"&gt;https://live.paloaltonetworks.com/docs/DOC-3120&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Ameya&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 18:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2153#M1595</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2012-09-13T18:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2154#M1596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can also try resetting the user-id manager with the command "debug user-id reset user-id manager type all" and also "debug software restart user-id" from the cli&lt;/P&gt;&lt;P&gt;Sandeep T&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2012 20:57:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2154#M1596</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2012-09-13T20:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2155#M1597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the suggestions and help. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like my PAN box is mapping users to IP's. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what I see what I run show user ip-user-mapping:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Ident. By User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Idle Timeout (s) Max. Timeout (s)&lt;/P&gt;&lt;P&gt;--------------- --------- -------------------------------- ---------------- ----------------&lt;/P&gt;&lt;P&gt;10.2.131.95&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in\amorse&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3499&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3499&lt;/P&gt;&lt;P&gt;10.134.193.219&amp;nbsp; AD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in\kwoodward&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3499&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3499&lt;/P&gt;&lt;P&gt;10.130.193.238&amp;nbsp; AD&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; in\bucstudent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3499&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3499&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run: show user group list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't get anything back. I'm thinking this is where the problem is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This looks odd to me too:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show user group-mapping state all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group Mapping(vsys1, type: active-directory): test&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bind DN&amp;nbsp;&amp;nbsp;&amp;nbsp; : &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:PANBOX@IN.SCU.K12.CA.US"&gt;PANBOX@IN.SCU.K12.CA.US&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : DC=in,DC=scu,DC=k12,DC=ca,DC=us&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Filter: (None)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Filter: (None)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Servers&amp;nbsp;&amp;nbsp;&amp;nbsp; : configured 1 servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.20.112(3268)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Proxy state: QUERY_SENT (no result back from agent)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Query agent: ADMASTER2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Result from:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: (Never)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Action Time: In 2 secs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Groups: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for everyone's support! Can't wait to get this going!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2012 18:19:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2155#M1597</guid>
      <dc:creator>jbaublitz</dc:creator>
      <dc:date>2012-09-14T18:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2156#M1598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the output, the agent has not responded back to the firewall with the groups. Make sure the agent and firewall have connectivity and the agent can reach the DC to pull groups. Can you try to bypass the agent and pull the groups directly from DC?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 15 Sep 2012 14:14:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2156#M1598</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-09-15T14:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2157#M1599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="j-post-author "&gt;&lt;STRONG&gt;&lt;A _jive_internal="true" class="jiveTT-hover-user jive-username-link active_link" data-avatarid="-1" data-externalid="" data-presence="null" data-userid="11170" data-username="jbaublitz" href="https://live.paloaltonetworks.com/people/jbaublitz" id="jive-1117019313873185924603"&gt;jbaublitz&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I got the same errors like You.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In my situation problem was in Device &amp;gt;&amp;nbsp; User Identyfication&amp;gt; Group Mapping Settigs &amp;gt; Group Include list - if you click on "+" you should see yor groups. I got error insted list of group.&lt;/P&gt;&lt;P&gt;To fix it go to Server Profiles &amp;gt; LDAP - server should be reached at 389 port according to &lt;/P&gt;&lt;P&gt;&lt;A href="http://technet.microsoft.com/en-us/library/dd772723%28v=ws.10%29.aspx"&gt;http://technet.microsoft.com/en-us/library/dd772723%28v=ws.10%29.aspx&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2012 06:52:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2157#M1599</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2012-09-19T06:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2158#M1600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you go to Device-&amp;gt;Authentication Profile-&amp;gt;(open profile up)-&amp;gt;Login Attribute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What value is listed there?&amp;nbsp; Mine was blank, and when I put in the value "sAMAccountName" everything started to work like magic.&amp;nbsp; Does that help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 04:24:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2158#M1600</guid>
      <dc:creator>etank</dc:creator>
      <dc:date>2012-09-21T04:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2159#M1601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you've already got that part working - have you looked at your Group Include List?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device-&amp;gt;User Identification-&amp;gt;Group Mapping Settings-&amp;gt;Group Include List (tab)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Expand your domain and then find the groups you want - then add them to the list... you can use these in your security policies if they are listed here.&amp;nbsp; Does that help?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2012 04:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2159#M1601</guid>
      <dc:creator>etank</dc:creator>
      <dc:date>2012-09-21T04:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: Want to create a security policy based on domain user group.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2160#M1602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Got it working... The problem was the PAN box was set to Proxy the groups from the agent to the Box. Support went in and turned off the proxy, and all the groups showed up... Thanks for everyone's help and advice. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Sep 2012 20:13:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/want-to-create-a-security-policy-based-on-domain-user-group/m-p/2160#M1602</guid>
      <dc:creator>jbaublitz</dc:creator>
      <dc:date>2012-09-24T20:13:26Z</dc:date>
    </item>
  </channel>
</rss>

