<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Users instead of Groups in Policies - Help please in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106830#M44846</link>
    <description>&lt;P&gt;Thank you for your reply Brandon, can you please elaborate a bit more on how you did it? Am I missing something ? On the Staff group I have users inside (Staff1, etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupMapping.png" style="width: 624px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5333iCE663633DA095EEE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GroupMapping.png" alt="GroupMapping.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spolicyrule.png" style="width: 710px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5334i982FC6B358A05706/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="spolicyrule.png" alt="spolicyrule.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupMappingConf.png" style="width: 624px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5335iBAA615A4069C45C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GroupMappingConf.png" alt="GroupMappingConf.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Aug 2016 18:51:16 GMT</pubDate>
    <dc:creator>zearth</dc:creator>
    <dc:date>2016-08-24T18:51:16Z</dc:date>
    <item>
      <title>Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106782#M44842</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm new to PA but I'm really enjoying it...anyway, I've read everything I could find aboud group mappings, and one very good link is&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321&lt;/A&gt; .. but it only show how to use a group in a policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it possible to use a "user" instead of a group in a policy? It seems I can only manage to retreive group info (user-id ip mappings are working through an Agent).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 17:08:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106782#M44842</guid>
      <dc:creator>zearth</dc:creator>
      <dc:date>2016-08-24T17:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106826#M44845</link>
      <description>&lt;P&gt;Yes, I'm able to build a security policy using a specific user ID and not just a security group.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 18:44:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106826#M44845</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-08-24T18:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106830#M44846</link>
      <description>&lt;P&gt;Thank you for your reply Brandon, can you please elaborate a bit more on how you did it? Am I missing something ? On the Staff group I have users inside (Staff1, etc)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupMapping.png" style="width: 624px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5333iCE663633DA095EEE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GroupMapping.png" alt="GroupMapping.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="spolicyrule.png" style="width: 710px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5334i982FC6B358A05706/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="spolicyrule.png" alt="spolicyrule.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="GroupMappingConf.png" style="width: 624px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5335iBAA615A4069C45C2/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="GroupMappingConf.png" alt="GroupMappingConf.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 18:51:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106830#M44846</guid>
      <dc:creator>zearth</dc:creator>
      <dc:date>2016-08-24T18:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106856#M44849</link>
      <description>&lt;P&gt;Generally speaking you would want to include the user domain in your Server Profile, it looks like you would have zearthlink. Try giving that a shot and see if it gives you options to your user list; it may also be a good idea to verify that you actually have the right permissions setup, PAs require more permissions then most server admins would feel is necessary&amp;nbsp;so often times I see them not actually have every permission that they need.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 19:47:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106856#M44849</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-24T19:47:45Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106864#M44850</link>
      <description>&lt;P&gt;Yeah like&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry﻿&lt;/a&gt;&amp;nbsp;said, I didn't have to do it from the group mapping, it's all probably because of a lack of permissions on the account you're using in the Palo to query AD. &amp;nbsp;When I create a new security rule I'm able to just enumerate the domain and find the correct user accounts that are necessary.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 20:25:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106864#M44850</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-08-24T20:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106865#M44851</link>
      <description>&lt;P&gt;Thank you Bpry for your comment. Unfortunately it didn't sort the issue out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for the account permissions, its the same I use for the user agent:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="panadminproperties.png" style="width: 421px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5336iAA2BFCBF585387B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="panadminproperties.png" alt="panadminproperties.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="userip.png" style="width: 696px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5337iB18B22DE82BA747F/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="userip.png" alt="userip.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I even already tried with the "administrator" account (it's only a lab so not really a concern &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; ) without success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If anyone have another idea please share it&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Wed, 24 Aug 2016 20:26:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/106865#M44851</guid>
      <dc:creator>zearth</dc:creator>
      <dc:date>2016-08-24T20:26:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/107324#M44873</link>
      <description>&lt;P&gt;It really sounds like you just don't have something configured properly on the AD side of things. Have you modified the properties on CIMV2 in WIM, have you actually enabled User Identification on the actual zone (this would explain why your accounts listed can't be used)? If you run&amp;nbsp;&lt;EM&gt;show user ip-user-mapping all&lt;/EM&gt; do you actually get anything listed or does nothing show up? You could verify&amp;nbsp;well have multiple issues here that are masquerading&amp;nbsp;as one&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 15:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/107324#M44873</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-08-25T15:20:19Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/107382#M44880</link>
      <description>&lt;P&gt;Hello Bpry,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for getting back to me again. I have user identification enabled on LAN, gave FULL permissions to the panadmin account and even tried the administrator account:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="zoneuserid.png" style="width: 710px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5346iE4B478F011069B93/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="zoneuserid.png" alt="zoneuserid.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CIMV2.png" style="width: 407px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5347i5955809A822E3E87/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="CIMV2.png" alt="CIMV2.png" /&gt;&lt;/span&gt;﻿&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="userip.png" style="width: 696px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5348i9F004B0F0B6C8F68/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="userip.png" alt="userip.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the user logged (staff1) and it's ip address but still can't filter by users, just groups &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 16:09:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/107382#M44880</guid>
      <dc:creator>zearth</dc:creator>
      <dc:date>2016-08-25T16:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Using Users instead of Groups in Policies - Help please</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/107410#M44881</link>
      <description>&lt;P&gt;Ok, I feel ashamed now..... It was working all along, &amp;nbsp;I just needed to start &lt;U&gt;&lt;STRONG&gt;typing&lt;/STRONG&gt;&lt;/U&gt; the username for it to recognize because by default the users don't appear on the list :|:|:|:|:| Not really intuitive &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt; .. days lost!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="user.png" style="width: 401px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/5349i5A28E781E34E7523/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="user.png" alt="user.png" /&gt;&lt;/span&gt;﻿&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I really appreciated your help on this guys, sorry for the wasted time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Thu, 25 Aug 2016 16:33:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/using-users-instead-of-groups-in-policies-help-please/m-p/107410#M44881</guid>
      <dc:creator>zearth</dc:creator>
      <dc:date>2016-08-25T16:33:00Z</dc:date>
    </item>
  </channel>
</rss>

