<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Group Mapping for Multi Domain Single forest in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-for-multi-domain-single-forest/m-p/75031#M41863</link>
    <description>&lt;P&gt;If I understand your explanation correctly, you are seeing users from domain B in their proper form (domainb\user) in the user-ip mapping. if you add a second LDAP server profile to match domain B groups, you should be able to also have domain B groups in the policy&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2016 09:27:35 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2016-03-22T09:27:35Z</dc:date>
    <item>
      <title>User-ID Group Mapping for Multi Domain Single forest</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-for-multi-domain-single-forest/m-p/75029#M41862</link>
      <description>&lt;P&gt;Hi everyone.&lt;/P&gt;
&lt;P&gt;I'm trying to setup a User-ID installation for our multi-domain Active Directory environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a rundown on what we have&lt;/P&gt;
&lt;P&gt;DomainA = Workstations, groups, users, servers, etc. The main domain where everything is conducted&lt;/P&gt;
&lt;P&gt;DomainB = legacy domain where some user accounts are located.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've installed the User-ID agent on a Windows VM running in DomainA and have configured the PA F/W to talk to DomainA for LDAP and User-ID.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Groups that I want to use as part of the Policy are located in DomainA. Those groups have members from DomainB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the monitor tab I can see users from DomainB being matched correctly and if I set the policy to a user directly it will match. However where I'm having issues is that if I specifiy a group in DomainA as part of the policy, it's not matching for the user in DomainB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So my question is (after that long winded explanation), can my wanted setup work or do I have to do thing differently?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 05:27:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-for-multi-domain-single-forest/m-p/75029#M41862</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-03-22T05:27:24Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Mapping for Multi Domain Single forest</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-for-multi-domain-single-forest/m-p/75031#M41863</link>
      <description>&lt;P&gt;If I understand your explanation correctly, you are seeing users from domain B in their proper form (domainb\user) in the user-ip mapping. if you add a second LDAP server profile to match domain B groups, you should be able to also have domain B groups in the policy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 09:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-for-multi-domain-single-forest/m-p/75031#M41863</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-03-22T09:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Group Mapping for Multi Domain Single forest</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-for-multi-domain-single-forest/m-p/75033#M41864</link>
      <description>&lt;P&gt;correct, in the monitor tab I can correctly see domainB\user being resolved.&lt;/P&gt;
&lt;P&gt;in the policy though, if I configure domainA\group as the user and domainB\user is a member of that group, it wasn't resolving the lookup to the group and the policy would fail.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure which group type to user Global, Domain Local, Universal. I have the LDAP server profile talking to the Global Catalog.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'll try with the second LDAP profile talking to domainB and see if that works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 10:45:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-group-mapping-for-multi-domain-single-forest/m-p/75033#M41864</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-03-22T10:45:33Z</dc:date>
    </item>
  </channel>
</rss>

