<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP User Group Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7168#M5296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've experienced this issue also within the GUI when connecting to large ldap directories... Workaround was to add the groups by the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Making sure to use full ldap path e.g&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set group-mapping GROUP_MAPPER group-include-list "cn=internet power users,ou=www groups,ou=groups,dc=xyz,dc=local"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 May 2012 15:27:43 GMT</pubDate>
    <dc:creator>ucteam</dc:creator>
    <dc:date>2012-05-04T15:27:43Z</dc:date>
    <item>
      <title>LDAP User Group Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7164#M5292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;We are trying to start building URL filtering.&amp;nbsp; I'm noticing that when I try and set groups in the "Group Include List" it stops at a certain letter and just gives me the "more" option but I can never finish populating the list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2012 18:07:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7164#M5292</guid>
      <dc:creator>mrsold</dc:creator>
      <dc:date>2012-04-26T18:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP User Group Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7165#M5293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How many groups do you have? If you have a very large number of groups (several hundred or more) then you could hit limits to number of groups that can be used in policy. If that is the case, then it is always recommended to filter groups to only those that you require in policies.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Richard&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Apr 2012 19:58:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7165#M5293</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2012-04-28T19:58:53Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP User Group Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7166#M5294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, and that is what I'm trying to do (filter).&amp;nbsp; But when I go into the filter section in the GUI is only lists groups up to a certina point and then just says, "More..." which I can't click on to populate more groups.&amp;nbsp; I've tried adding them via CLI but it never takes the addition correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Apr 2012 13:13:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7166#M5294</guid>
      <dc:creator>mrsold</dc:creator>
      <dc:date>2012-04-30T13:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP User Group Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7167#M5295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are your groups nested in a multi tier scenario? If so, could you perhaps consider starting the search (Base DN) to be more indented?&lt;/P&gt;&lt;P&gt;The delay in being able to pull nested groups may be causing issues and so you may be getting timed out, before the groups are read correctly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 May 2012 23:00:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7167#M5295</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2012-05-02T23:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP User Group Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7168#M5296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've experienced this issue also within the GUI when connecting to large ldap directories... Workaround was to add the groups by the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Making sure to use full ldap path e.g&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set group-mapping GROUP_MAPPER group-include-list "cn=internet power users,ou=www groups,ou=groups,dc=xyz,dc=local"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 May 2012 15:27:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-user-group-issue/m-p/7168#M5296</guid>
      <dc:creator>ucteam</dc:creator>
      <dc:date>2012-05-04T15:27:43Z</dc:date>
    </item>
  </channel>
</rss>

