<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User in different AD groups in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-in-different-ad-groups/m-p/42966#M31547</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we want to enforce a policy with user groups from AD. USER ID actually works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following scenario: A single User (e.g. Harry) belongs to different AD groups (e.g. group1 &amp;amp; group2). The policy works with different URL Filtering profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy 1 will have Source "group1" and Policy 2 will have Source "group2" as Objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy 1 is positioned before Policy 2. If User Harry wants to try to reach an URL which is allowed in Policy 2 (group2) it will never match, because Policy 1 matches always for that User regardless if the URL is allowed or blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone an idea to fix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Mar 2011 12:48:27 GMT</pubDate>
    <dc:creator>Haecker</dc:creator>
    <dc:date>2011-03-01T12:48:27Z</dc:date>
    <item>
      <title>User in different AD groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-in-different-ad-groups/m-p/42966#M31547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we want to enforce a policy with user groups from AD. USER ID actually works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following scenario: A single User (e.g. Harry) belongs to different AD groups (e.g. group1 &amp;amp; group2). The policy works with different URL Filtering profiles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy 1 will have Source "group1" and Policy 2 will have Source "group2" as Objects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Policy 1 is positioned before Policy 2. If User Harry wants to try to reach an URL which is allowed in Policy 2 (group2) it will never match, because Policy 1 matches always for that User regardless if the URL is allowed or blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone an idea to fix?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 12:48:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-in-different-ad-groups/m-p/42966#M31547</guid>
      <dc:creator>Haecker</dc:creator>
      <dc:date>2011-03-01T12:48:27Z</dc:date>
    </item>
    <item>
      <title>Re: User in different AD groups</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-in-different-ad-groups/m-p/42967#M31548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Today you need to create an exception URL Profile and Security Rule to handle these types of cases.&amp;nbsp; It is not pretty, but it does work.&amp;nbsp; There will be enhancements to help simplify this type of policy in a future release.&amp;nbsp; It is possible it may come before the end of this year.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Mar 2011 16:42:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-in-different-ad-groups/m-p/42967#M31548</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2011-03-01T16:42:33Z</dc:date>
    </item>
  </channel>
</rss>

