<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't authenticate users in nested groups (AD, Radius) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-authenticate-users-in-nested-groups-ad-radius/m-p/49327#M36341</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a rule to allow access to Facebook.&amp;nbsp; The rule works if I list individual users, but not groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a single forest with 2 child domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Universal Group "FB Allowed"&amp;nbsp; has the following groups as members: "OU1 FB Allowed" and "OU2 FB Allowed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These universal groups contain members from both domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to avoid having to maintain multiple groups in the rules.&amp;nbsp; As far as the Palo is concerned, I want it to read from 1 group and allow local admins at each site to populate their users into their respective groups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Aug 2011 15:32:13 GMT</pubDate>
    <dc:creator>aindelicato</dc:creator>
    <dc:date>2011-08-11T15:32:13Z</dc:date>
    <item>
      <title>Can't authenticate users in nested groups (AD, Radius)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-authenticate-users-in-nested-groups-ad-radius/m-p/49327#M36341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a rule to allow access to Facebook.&amp;nbsp; The rule works if I list individual users, but not groups.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a single forest with 2 child domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Universal Group "FB Allowed"&amp;nbsp; has the following groups as members: "OU1 FB Allowed" and "OU2 FB Allowed"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These universal groups contain members from both domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to avoid having to maintain multiple groups in the rules.&amp;nbsp; As far as the Palo is concerned, I want it to read from 1 group and allow local admins at each site to populate their users into their respective groups.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Aug 2011 15:32:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-authenticate-users-in-nested-groups-ad-radius/m-p/49327#M36341</guid>
      <dc:creator>aindelicato</dc:creator>
      <dc:date>2011-08-11T15:32:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can't authenticate users in nested groups (AD, Radius)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-authenticate-users-in-nested-groups-ad-radius/m-p/49328#M36342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, I believe you have 2 separate user agents configured 1 for each domain.&lt;/P&gt;&lt;P&gt;Are you able to read group information?&lt;/P&gt;&lt;P&gt;&amp;gt; &lt;STRONG style="color:red"&gt;debug device-server dump user-group name “domain\groupname”&lt;/STRONG&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Aug 2011 01:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-authenticate-users-in-nested-groups-ad-radius/m-p/49328#M36342</guid>
      <dc:creator>ukhapre</dc:creator>
      <dc:date>2011-08-14T01:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't authenticate users in nested groups (AD, Radius)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-authenticate-users-in-nested-groups-ad-radius/m-p/49329#M36343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the same problem in a demo install and I opened a case. That was a few months ago with a 4.x release. Unfortunately support was not willing to replicate the issue in their Lab and I did not want to bother the prospect with onsite troubleshooting sessions during a demo installation....&amp;nbsp; So the case was dropped (case number 00038670), but the problem is still there, just did not have time to setup the whole scenario again in our own Lab and open up another case.&amp;nbsp; Roland&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 11:57:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-authenticate-users-in-nested-groups-ad-radius/m-p/49329#M36343</guid>
      <dc:creator>gafrol</dc:creator>
      <dc:date>2011-08-16T11:57:18Z</dc:date>
    </item>
  </channel>
</rss>

