<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP and trusted domains in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50979#M37519</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I use Active Directory groups to control my content filter policies.&amp;nbsp; One of the groups is currently set to Domain Local as it contains a member of one of the trusted domains.&amp;nbsp; I have an agent running in this trusted domain and the PAN appliance can properly detect the username.&amp;nbsp; When I look in AD I can see the membership containing members of both domains.&amp;nbsp; LDAP is setup to use port 3268 instead of 389.&amp;nbsp; When I type the show user group name DOMAIN\unblock_craigslist all of the members of my local domain are listed, just not the members from the trusted domain.&amp;nbsp; Does anyone know how to handle group memberships that have members from a trusted domain.&amp;nbsp; Keep in mind that these trusts are completely separate forests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 27 Jun 2013 20:06:05 GMT</pubDate>
    <dc:creator>nthen</dc:creator>
    <dc:date>2013-06-27T20:06:05Z</dc:date>
    <item>
      <title>LDAP and trusted domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50979#M37519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I use Active Directory groups to control my content filter policies.&amp;nbsp; One of the groups is currently set to Domain Local as it contains a member of one of the trusted domains.&amp;nbsp; I have an agent running in this trusted domain and the PAN appliance can properly detect the username.&amp;nbsp; When I look in AD I can see the membership containing members of both domains.&amp;nbsp; LDAP is setup to use port 3268 instead of 389.&amp;nbsp; When I type the show user group name DOMAIN\unblock_craigslist all of the members of my local domain are listed, just not the members from the trusted domain.&amp;nbsp; Does anyone know how to handle group memberships that have members from a trusted domain.&amp;nbsp; Keep in mind that these trusts are completely separate forests.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 20:06:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50979#M37519</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-06-27T20:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and trusted domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50981#M37521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can query each domain pretty easy.&amp;nbsp; The issue I am running into is the Group Mapping.&amp;nbsp; It does not show the members of the trusted domain.&amp;nbsp; I can identify the user properly, just not do group based rules.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 20:31:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50981#M37521</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-06-27T20:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and trusted domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50982#M37522</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the output of the following command not show you all the groups a specific user is part of?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; show user user-IDs &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 20:35:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50982#M37522</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-06-27T20:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and trusted domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50983#M37523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My trusted domain user does not show up in this list.&amp;nbsp; All other local domain users do and show the correct group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 20:38:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50983#M37523</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-06-27T20:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and trusted domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50984#M37524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That means that we are not pulling users or groups from the trusted user at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the Palo Alto to be able to do that we need to have a group mapping setting for the trusted domain as well as the local domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that is the missing link here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 20:43:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50984#M37524</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-06-27T20:43:16Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP and trusted domains</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50985#M37525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All my groups are in the local domain and I just add the trusted users to it so I can keep all my groups together.&amp;nbsp; I think this is due to the ForiegnSecurityPrincipals in Active Directory.&amp;nbsp; When I put an LDAP browser on it, I can see my local users and a SID of the remote user.&amp;nbsp; I don't think the PAN can resolve trusted domain users since it doesn't come back from LDAP that way.&amp;nbsp; I was reading about a way to trick the agent on the remote end to send a different domain name.&amp;nbsp; This would work for me if anyone knows where to set it since I have the same user in both domains for the Global Protect to work correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Jun 2013 20:51:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-and-trusted-domains/m-p/50985#M37525</guid>
      <dc:creator>nthen</dc:creator>
      <dc:date>2013-06-27T20:51:24Z</dc:date>
    </item>
  </channel>
</rss>

