<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP - Group Mapping with Child Domain users in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-group-mapping-with-child-domain-users/m-p/22405#M16334</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's it, thank you very much dorm! I didn't know that Global Catalog uses a different port. 3269 works with SSL by the way. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Jun 2013 21:00:29 GMT</pubDate>
    <dc:creator>oschuler</dc:creator>
    <dc:date>2013-06-11T21:00:29Z</dc:date>
    <item>
      <title>LDAP - Group Mapping with Child Domain users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-group-mapping-with-child-domain-users/m-p/22403#M16332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We'd like to use an Active Directory group in our root domain (e.g. "company.com") to control GlobalProtect authentications. Let's name this AD group "VPN Access" (it's a "Universal" Security Group). It contains user objects from the root domain itself but also from other subordinate domains like "branch1.example.com". Unfortunately, our PA-2050 ignores all foreign users added to this group. All root-domain users are visible when executing the following CLI command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; show user group name "cn=vpn access,ou=usergroups,dc=example,dc=com"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The LDAP profile connects to a Global Catalog Active Directory server in the root domain ("example.com") and is configured with the following settings on the PA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="LDAP.png" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/6880_LDAP.png" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to force the PA to recognize the sub-domain users in this parent domain group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 19:37:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-group-mapping-with-child-domain-users/m-p/22403#M16332</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-06-11T19:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - Group Mapping with Child Domain users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-group-mapping-with-child-domain-users/m-p/22404#M16333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i belive you should configure the port for the global catalog and not the regular ldap port:&lt;/P&gt;&lt;P&gt;if this DC is GC then configure:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-family: 'Segoe UI', Arial, Verdana, Tahoma, sans-serif; background-color: #ffffff;"&gt;3269 - for ssl connection (this i am not sure the defaults, you may try first unencrypted)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #2a2a2a; background-color: #ffffff; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif;"&gt;3268- for unencrypted connection&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 20:23:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-group-mapping-with-child-domain-users/m-p/22404#M16333</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2013-06-11T20:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - Group Mapping with Child Domain users</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-group-mapping-with-child-domain-users/m-p/22405#M16334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's it, thank you very much dorm! I didn't know that Global Catalog uses a different port. 3269 works with SSL by the way. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Jun 2013 21:00:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-group-mapping-with-child-domain-users/m-p/22405#M16334</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-06-11T21:00:29Z</dc:date>
    </item>
  </channel>
</rss>

