<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About updating AD group membership in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34393#M25242</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a domain with 10,000 - 12,000 accounts in the domain with no issues. We have user-id agents on two servers (redundancy) polling 12 domains across a total of 39 Domain controllers without issue.&amp;nbsp; Keeping in mind the group membership polling interval mentioned above in the previous posts.&amp;nbsp; The polling interval is a balancing act between performance hit on the servers vs. speed of updating changes to group membership. We will add the user to the rule and commit if there is an urgency to the access request while waiting for the polling interval to update the firewall with the group membership changes (usually an addition).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Dec 2013 02:40:40 GMT</pubDate>
    <dc:creator>HITSSEC</dc:creator>
    <dc:date>2013-12-26T02:40:40Z</dc:date>
    <item>
      <title>About updating AD group membership</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34390#M25239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I configured LDAP profile and update from AD DC&lt;/P&gt;&lt;P&gt;2. AD group named domain-users has about 10900 user&lt;/P&gt;&lt;P&gt;3. Customer created new user and applied new user to domain-users group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I tried to refresh a group-mapping information by debug command. But PAN could not be updated domain-users group information and refreshing member of group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. I created new group and applied new user to new group&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PAN could be updated and bring a new-group with their membership.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I have a question. How many PAN recognize a group-member from AD? or PAN has got a limit of max group membership from AD?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Roh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Dec 2013 02:24:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34390#M25239</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-12-20T02:24:55Z</dc:date>
    </item>
    <item>
      <title>Re: About updating AD group membership</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34391#M25240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default existing group mapping is updated after 1 hour, you can change the settings. Please refer bellow mentioned document for more details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4994" style="font-size: 10pt; line-height: 1.5em;"&gt;https://live.paloaltonetworks.com/docs/DOC-4994&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have further questions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Dec 2013 00:24:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34391#M25240</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2013-12-26T00:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: About updating AD group membership</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34392#M25241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can force group-mapping refresh with following command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3294"&gt;https://live.paloaltonetworks.com/docs/DOC-3294&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Dec 2013 00:34:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34392#M25241</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2013-12-26T00:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: About updating AD group membership</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34393#M25242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a domain with 10,000 - 12,000 accounts in the domain with no issues. We have user-id agents on two servers (redundancy) polling 12 domains across a total of 39 Domain controllers without issue.&amp;nbsp; Keeping in mind the group membership polling interval mentioned above in the previous posts.&amp;nbsp; The polling interval is a balancing act between performance hit on the servers vs. speed of updating changes to group membership. We will add the user to the rule and commit if there is an urgency to the access request while waiting for the polling interval to update the firewall with the group membership changes (usually an addition).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Phil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Dec 2013 02:40:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34393#M25242</guid>
      <dc:creator>HITSSEC</dc:creator>
      <dc:date>2013-12-26T02:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: About updating AD group membership</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34394#M25243</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;you could find more information here&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-5939"&gt;https://live.paloaltonetworks.com/docs/DOC-5939&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;greg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Dec 2013 11:18:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/about-updating-ad-group-membership/m-p/34394#M25243</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-12-26T11:18:32Z</dc:date>
    </item>
  </channel>
</rss>

