<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User/Group based policy questions in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-based-policy-questions/m-p/35249#M25895</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I managed to pass the first hurdle. Pushing user-id/group based policies via Panorama is possible. Under Panorama -&amp;gt; Device Groups -&amp;gt; There is an option called as "Master Device" (refer screenshot below). If you add a device here and if that device has the LDAP, Group Mapping etc. configured then Panorama can pull the user/group information from it. I was able to create an active directory group based policy via Panorama. Now the next pending is, do I need to have Group Mapping created on the individual device where the policy is pushed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="304" src="https://live.paloaltonetworks.com/legacyfs/online/5505_pastedImage_0.png" style="width: 676px; height: 304px;" width="676" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Feb 2013 14:48:09 GMT</pubDate>
    <dc:creator>Sly_Cooper</dc:creator>
    <dc:date>2013-02-01T14:48:09Z</dc:date>
    <item>
      <title>User/Group based policy questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-based-policy-questions/m-p/35248#M25894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a need to configured user/group based policy. I having difficulties with the same and have multiple questions. I hope someone will help me with the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. We push all our policies from Panorama. Can I configure user/group based policy on Panorama and push to all firewalls?&lt;/P&gt;&lt;P&gt;2. I have pushed the LDAP config from Panorama to all firewalls. Can I use the same in group mapping?&lt;/P&gt;&lt;P&gt;3. Do I need to configure group mapping before using the group or users in that group in the policy?&lt;/P&gt;&lt;P&gt;4. I have a scenario wherein I have configured local LDAP profile along with the Panorama pushed one. Although I can browse the group and create the group mapping, I cannot find any users which are part of that group from CLI&lt;/P&gt;&lt;P&gt;5. I have also found out that PA firewalls have issue browsing distribution groups. It can find security groups in active directory without any problem. Did anyone come across the same or know this limitation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already have a support case open however there is no resolution yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 12:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-based-policy-questions/m-p/35248#M25894</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2013-01-29T12:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: User/Group based policy questions</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-group-based-policy-questions/m-p/35249#M25895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I managed to pass the first hurdle. Pushing user-id/group based policies via Panorama is possible. Under Panorama -&amp;gt; Device Groups -&amp;gt; There is an option called as "Master Device" (refer screenshot below). If you add a device here and if that device has the LDAP, Group Mapping etc. configured then Panorama can pull the user/group information from it. I was able to create an active directory group based policy via Panorama. Now the next pending is, do I need to have Group Mapping created on the individual device where the policy is pushed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="jiveImage" height="304" src="https://live.paloaltonetworks.com/legacyfs/online/5505_pastedImage_0.png" style="width: 676px; height: 304px;" width="676" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 14:48:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-group-based-policy-questions/m-p/35249#M25895</guid>
      <dc:creator>Sly_Cooper</dc:creator>
      <dc:date>2013-02-01T14:48:09Z</dc:date>
    </item>
  </channel>
</rss>

