<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nested groups problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64815#M38793</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Already using 7.0.2.&lt;/P&gt;&lt;P&gt;Seems this is not supported.&lt;/P&gt;&lt;P&gt;Can anyone confirm that ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 18 Sep 2015 21:05:26 GMT</pubDate>
    <dc:creator>PanIst</dc:creator>
    <dc:date>2015-09-18T21:05:26Z</dc:date>
    <item>
      <title>Nested groups problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64688#M38737</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3 domain and single forest.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;(root domain)&amp;nbsp; named as domainA&lt;/STRONG&gt; and domainB and domainC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we created 3 LDAP profile for each domain.&lt;/P&gt;&lt;P&gt;we can see members from all domains.&lt;/P&gt;&lt;P&gt;we can see groups for each domain also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But problem is, if we create a group named ALLVPN in root domainA and there are 3 members in this group.&lt;/P&gt;&lt;P&gt;member1-groupC which is member of root domainA&lt;/P&gt;&lt;P&gt;member2-groupD which is member of domainB&lt;/P&gt;&lt;P&gt;member3-groupE which is member of domainC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group name ALLVPN only shows member of groupC.&lt;/P&gt;&lt;P&gt;Does paloalto support this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we tried also port 3268 instead of 389 but nothing changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Sep 2015 14:17:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64688#M38737</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2015-09-16T14:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Nested groups problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64786#M38773</link>
      <description>&lt;P&gt;We experience the same...Palo Alto does not support nesting unless it has change in 7.0 and up.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 11:45:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64786#M38773</guid>
      <dc:creator>lewis</dc:creator>
      <dc:date>2015-09-18T11:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Nested groups problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64793#M38779</link>
      <description>&lt;P&gt;Hi Panlst&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nesting should be supported if the LDAP profile is set to ActiveDirectory, some additional improvements were introduced in 7.0 that should also allow nesting if the ldap is set to "other"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may need to verify your current ldap setting and change it to ActiveDirectory if you have not done so already, alternatively upgrading to 7.0 may help resolve the issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 13:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64793#M38779</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-09-18T13:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Nested groups problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64815#M38793</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;Already using 7.0.2.&lt;/P&gt;&lt;P&gt;Seems this is not supported.&lt;/P&gt;&lt;P&gt;Can anyone confirm that ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2015 21:05:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/64815#M38793</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2015-09-18T21:05:26Z</dc:date>
    </item>
    <item>
      <title>Re: Nested groups problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/65411#M39063</link>
      <description>&lt;P&gt;It is definitely possible to achieve the results you are looking for, but it may require some reconfiguration of your underlying groups. Group nesting is supported, and will resolve to a total depth of 10 levels.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, as you are wanting to include group members from multiple domains in the same forest, you will need to configure your group mapping connector against a Global Catalog.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You indicate that you made this configuration change, but it had no effect. That is likely because of the underlying group type that you were trying to include. The only groups with members that will be visible in the Global Catalog with members will be Universal Groups. The group being nested is currently probably a Domain Local group, and is not in the Global Catalog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a Universal Group in the forest root domain, containing a single nested group:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/541iE6A57F67D8291A69/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Screen Shot 2015-10-02 at 11.56.28 AM.png" title="Screen Shot 2015-10-02 at 11.56.28 AM.png" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The Nested Group contains users from 3 domains in the forest:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/542i4D8376FC3F9E369F/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Screen Shot 2015-10-02 at 12.14.06 PM.png" title="Screen Shot 2015-10-02 at 12.14.06 PM.png" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Showing the group shows members for all domains being included:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;admin@PA-200&amp;gt; show user group name "lab\demo universal group nesting"&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;short name:&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;lab\demo universal group nesting&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;source type: service&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;source:&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Get_Users_From_root&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[1 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;] acme\acmeuser&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[2 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;] acme\administrator&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[3 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;] lab\administrator&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[4 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;] panw\silliker&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[5 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;] panw\jruiz&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;[6 &lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;] lab\testuser&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2015 16:17:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/65411#M39063</guid>
      <dc:creator>asilliker</dc:creator>
      <dc:date>2015-10-02T16:17:29Z</dc:date>
    </item>
    <item>
      <title>Re: Nested groups problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/66477#M39215</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Config is the same but did not work.Because Multidomain environment can be on same tree but also not.&lt;/P&gt;
&lt;P&gt;Here we have multidomain with different tree but same forest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Paloalto seems to be that is not supported&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 13:04:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/nested-groups-problem/m-p/66477#M39215</guid>
      <dc:creator>PanIst</dc:creator>
      <dc:date>2015-10-13T13:04:03Z</dc:date>
    </item>
  </channel>
</rss>

