<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: blocking machines from AD-group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30618#M22408</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this whould be a really nice feature. i've only seen that on my checkpoint systems, appliances from CS or BC are missing that feature too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jan 2013 08:05:48 GMT</pubDate>
    <dc:creator>skemena</dc:creator>
    <dc:date>2013-01-15T08:05:48Z</dc:date>
    <item>
      <title>blocking machines from AD-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30615#M22405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to block outgoing traffic, from an active-directory group containing machines?&lt;/P&gt;&lt;P&gt;blocking traffic by username works fine, but i want to use the machine ad group rather than entering all machines by fqdn or ip in an address group of objects on my pa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'm using a pa-3020 on pan-os 5.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2013 09:28:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30615#M22405</guid>
      <dc:creator>skemena</dc:creator>
      <dc:date>2013-01-14T09:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: blocking machines from AD-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30616#M22406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is not possible as user-ip-mapping is done only for Active directory users and not the for the Computers. So it is not possible to block the traffic from machines in an AD group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2013 17:55:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30616#M22406</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-01-14T17:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: blocking machines from AD-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30617#M22407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you think is the probability to see this in future or is there perhaps already an active request for enhancement available?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because it would be really nice if one could combine userid and machineid when setting up rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Jan 2013 19:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30617#M22407</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-01-14T19:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: blocking machines from AD-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30618#M22408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this whould be a really nice feature. i've only seen that on my checkpoint systems, appliances from CS or BC are missing that feature too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 08:05:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/30618#M22408</guid>
      <dc:creator>skemena</dc:creator>
      <dc:date>2013-01-15T08:05:48Z</dc:date>
    </item>
    <item>
      <title>Re: blocking machines from AD-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/393263#M90997</link>
      <description>&lt;P&gt;Crap this thread is from 2013 and Palo appears to still not be able to map AD Machines for use?&lt;/P&gt;&lt;P&gt;That is going to make this migration from CheckPoint a lot more work and completely change our processes for allowing the help desk to take care of server internet access requests without the network group needing to be involved! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Honestly I am not sure why this hasn't been done as the CheckPoint Identity Collector gathers AD security the same way as the Palo Windows User-ID Agent is... CheckPoint gets the needed information and is it able to do AD Machine mappings so Machines and Machine Groups can be used in access policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Shouldn't the Palo User-ID Agent be capable of the same?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 12:59:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/393263#M90997</guid>
      <dc:creator>DIEHARD</dc:creator>
      <dc:date>2021-03-24T12:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: blocking machines from AD-group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/405382#M91999</link>
      <description>&lt;P&gt;Could you also please provide me any documentation on which I can divert the traffic from a group of users in Active Directory to a specific network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two internet connection and I am trying to splitting the group of users in Active Directory to different internet connection.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2021 02:34:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/blocking-machines-from-ad-group/m-p/405382#M91999</guid>
      <dc:creator>ChaffeySC</dc:creator>
      <dc:date>2021-05-07T02:34:13Z</dc:date>
    </item>
  </channel>
</rss>

