<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use wildcard in user/group based policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/use-wildcard-in-user-group-based-policy/m-p/139552#M48134</link>
    <description>&lt;P&gt;Hi Andrea,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're using the syslog method for your user mapping then I believe that you can't use group mapping with this method. If you want to configure group mapping then you'll need to be using a directory service such as Active Directory or eDirectory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the Group Mapping document for more info and how you can enable this in your network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/user-id-concepts#33876" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/user-id-concepts#33876&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A different method would be to enter a source IP range in the source field of your security policy effectively everyone in your internal network uses this rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Thu, 26 Jan 2017 11:47:18 GMT</pubDate>
    <dc:creator>bmorris1</dc:creator>
    <dc:date>2017-01-26T11:47:18Z</dc:date>
    <item>
      <title>Use wildcard in user/group based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-wildcard-in-user-group-based-policy/m-p/139539#M48132</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;We have a Splunk Server that sends to your id-agent (on a windows server) the information of guest users.&lt;/P&gt;&lt;P&gt;Now on PA We can se user@acme.com in the logs, is possbile for us create a rule for all users from acme, without define each user?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So a group policy without LDAP group.&lt;/P&gt;&lt;P&gt;We want to set in the field "source user", something like *@acme.com.&lt;/P&gt;&lt;P&gt;It is possible?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;BR /&gt;Andrea Acampa&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 10:46:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-wildcard-in-user-group-based-policy/m-p/139539#M48132</guid>
      <dc:creator>AndreaAcampa</dc:creator>
      <dc:date>2017-01-26T10:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Use wildcard in user/group based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-wildcard-in-user-group-based-policy/m-p/139552#M48134</link>
      <description>&lt;P&gt;Hi Andrea,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you're using the syslog method for your user mapping then I believe that you can't use group mapping with this method. If you want to configure group mapping then you'll need to be using a directory service such as Active Directory or eDirectory.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the Group Mapping document for more info and how you can enable this in your network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/user-id-concepts#33876" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/71/pan-os/pan-os/user-id/user-id-concepts#33876&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A different method would be to enter a source IP range in the source field of your security policy effectively everyone in your internal network uses this rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope this helps,&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 11:47:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-wildcard-in-user-group-based-policy/m-p/139552#M48134</guid>
      <dc:creator>bmorris1</dc:creator>
      <dc:date>2017-01-26T11:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: Use wildcard in user/group based policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/use-wildcard-in-user-group-based-policy/m-p/139599#M48151</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;your reply has been very useful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jan 2017 15:49:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/use-wildcard-in-user-group-based-policy/m-p/139599#M48151</guid>
      <dc:creator>AndreaAcampa</dc:creator>
      <dc:date>2017-01-26T15:49:59Z</dc:date>
    </item>
  </channel>
</rss>

