<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Group Mapping for Domains with Non-contiguous namespace in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77921#M42749</link>
    <description>&lt;P&gt;While I've removed the actual domains and am not displaying the targeted DCs within the domains for enumeration, I hope you get the context&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LDAP.JPG" style="width: 575px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4001i0224E4CB56841183/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LDAP.JPG" alt="LDAP.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of the 8 domains all 8 are unique domains not following contiguous DNS name space. &amp;nbsp;We use 4 UIAs, merely for load sharing purposes, that use same same service account in a single domain. &amp;nbsp;Our UIAs can target all 8 domains because of a domain trust which we've established.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For LDAP profile themselves we do use specific SAs (service accounts) which exist in the respective domains.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Following this contruct I've had no issues matching security group policy with associated user tracking.&lt;/P&gt;</description>
    <pubDate>Wed, 11 May 2016 13:09:53 GMT</pubDate>
    <dc:creator>Brandon_Wertz</dc:creator>
    <dc:date>2016-05-11T13:09:53Z</dc:date>
    <item>
      <title>Group Mapping for Domains with Non-contiguous namespace</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77898#M42741</link>
      <description>&lt;P&gt;Hi I'm attempting to implement userID on PAN-OS 7.0.6 within a multi-domain forest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All of our workstations exist on one domain and users logging into those workstations exist on another domain within the same forest. I have the UserID agent setup on a member server on the workstation domain and it can correctly map the IP address to usernames on the user domain.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The issue I'm having is that within the policy if I set a group name in the workstation domain, it cannot match to the username which is being correctly identified within the monitor tab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've seen articles dealing with multiple domains in a single forest but they tend to assume that the domains all have a contiguous DNS name space. Our environment doesn't have that, the user domain and workstation domain names are completley different (legacy reasons, I dont like it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone dealt with this before in the past?&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 04:59:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77898#M42741</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-05-11T04:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Group Mapping for Domains with Non-contiguous namespace</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77921#M42749</link>
      <description>&lt;P&gt;While I've removed the actual domains and am not displaying the targeted DCs within the domains for enumeration, I hope you get the context&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LDAP.JPG" style="width: 575px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4001i0224E4CB56841183/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="LDAP.JPG" alt="LDAP.JPG" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of the 8 domains all 8 are unique domains not following contiguous DNS name space. &amp;nbsp;We use 4 UIAs, merely for load sharing purposes, that use same same service account in a single domain. &amp;nbsp;Our UIAs can target all 8 domains because of a domain trust which we've established.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For LDAP profile themselves we do use specific SAs (service accounts) which exist in the respective domains.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Following this contruct I've had no issues matching security group policy with associated user tracking.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 13:09:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77921#M42749</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-05-11T13:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: Group Mapping for Domains with Non-contiguous namespace</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77923#M42750</link>
      <description>&lt;P&gt;Here's a snippet of a user policy I'm using:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy.png" style="width: 39px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/4002i8BF8DCD5BB93B144/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Policy.png" alt="Policy.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm successfully able to see these unique security groups in the different domains. &amp;nbsp;While our UIA enviornment which uses a service account in only 1 of the 8 domains can target users which exist in all 8 of the unique domains&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 13:14:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77923#M42750</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-05-11T13:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Group Mapping for Domains with Non-contiguous namespace</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77976#M42773</link>
      <description>&lt;P&gt;Hey thanks for the reply, it certainly does help. I have a couple of follow up questions if you dont mind, just to help me get it clear in my head.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Do you have cross domain group memberships for users being resolved correctly (ie. you set a group in a policy from domain1 and that group has a member from domain2 in it)&lt;/P&gt;
&lt;P&gt;2) For each of the LDAP profiles you use for the each of the domain are you using one Bind user per domain or a single Bind user for all domains? Are you connecting to LDAP port (389) or the Global Catalog (3268)&lt;/P&gt;
&lt;P&gt;3) Do you have the same number of Group Mapping profiles for each of the domains? Are you setting the User Domain variable and just keeping the rest of the variables standard.&lt;/P&gt;
&lt;P&gt;4) If I understand your explanation, you have 4 servers running the UserID Agent for load sharing and they are all member servers in a single domain using the one service account and they can match IP address to Username across all domains due to the trust?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for you help, I really appreciate it, this'll get me out of jam if I get it going.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 06:30:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/77976#M42773</guid>
      <dc:creator>jezkerwin</dc:creator>
      <dc:date>2016-05-12T06:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Group Mapping for Domains with Non-contiguous namespace</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/78132#M42838</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/40422"&gt;@jezkerwin﻿&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Do you have cross domain group memberships for users being resolved correctly (ie. you set a group in a policy from domain1 and that group has a member from domain2 in it)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No. &amp;nbsp;Each security group has user accounts in the respective domains&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) For each of the LDAP profiles you use for the each of the domain are you using one Bind user per domain or a single Bind user for all domains? Are you connecting to LDAP port (389) or the Global Catalog (3268)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1 Bind DN per domain. &amp;nbsp;LDAP/389&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) Do you have the same number of Group Mapping profiles for each of the domains? Are you setting the User Domain variable and just keeping the rest of the variables standard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yeah, just the default settings minus Base/Bind DN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4) If I understand your explanation, you have 4 servers running the UserID Agent for load sharing and they are all member servers in a single domain using the one service account and they can match IP address to Username across all domains due to the trust?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes. &amp;nbsp;Essentially domains A, B, C, D, E, F, G, H. &amp;nbsp;The UIAs are loaded on a 2012 server in domain "A" using a service account which exists in domain "A", which for all intents and purposes is the "parent" domain. &amp;nbsp;There are domain trusts with domain A and every other domain. In this contstruct we're getting user attribution from the other domains.&lt;/P&gt;</description>
      <pubDate>Mon, 16 May 2016 12:52:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-for-domains-with-non-contiguous-namespace/m-p/78132#M42838</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-05-16T12:52:42Z</dc:date>
    </item>
  </channel>
</rss>

