<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Group Mapping vs Authentication Profile in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187160#M56997</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the Authentication Profile you select the specific users and groups that are allowed to authenticate with this profile. If you don’t add entries, no users can authenticate.&lt;/P&gt;
&lt;P&gt;In the mapping you can&lt;SPAN&gt;&amp;nbsp;control which groups are&amp;nbsp;retrieved from LDAP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this clarifies the difference between the 2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2017 11:12:26 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2017-11-15T11:12:26Z</dc:date>
    <item>
      <title>Group Mapping vs Authentication Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187150#M56994</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is what we want to do:&lt;/P&gt;&lt;P&gt;1. Implement a security policy rule based on user group membership&lt;/P&gt;&lt;P&gt;2. There is no User ID using any Agent. The users will authenticate using captive portal.&lt;/P&gt;&lt;P&gt;3. Firewall will use LDAP to retrieve group mapping&lt;/P&gt;&lt;P&gt;4. PAN OS 7.1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's the question:&lt;/P&gt;&lt;P&gt;Assume that I want to allow only users from LDAP Group "HR" in the security policy. Then I create a LDAP Server Profile and then where do I need to mention the group:&lt;/P&gt;&lt;P&gt;1. In the Authentication Profile &amp;gt; Advanced &amp;gt; Allow List ??&amp;nbsp; &amp;nbsp; OR&lt;/P&gt;&lt;P&gt;2. In User IDentification &amp;gt; Group Mapping Settings??&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR both?&lt;/P&gt;&lt;P&gt;What is the purpose of each of the above settings? I am confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;R&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 10:31:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187150#M56994</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2017-11-15T10:31:53Z</dc:date>
    </item>
    <item>
      <title>Re: Group Mapping vs Authentication Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187157#M56995</link>
      <description>&lt;P&gt;there maybe more than 1 answer to this, depends on who is allowed to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i will assume that all users auth via your ldap authentication profile. so set this to "any"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;use your ldap server in group mapping settings, and select the groups you want to include in your policies.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in your HR policy just add source HR group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so... auth profile is for users allowed to authenticate. (you will still need group mapping if drilling down to group level)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;probably confused things... happy to re post if required...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 10:54:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187157#M56995</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-15T10:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Group Mapping vs Authentication Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187159#M56996</link>
      <description>&lt;P&gt;The auth profile controls who is allowed to authenticate&lt;/P&gt;
&lt;P&gt;The group mapping controls which groups are learned from LDAP (to be used in security policy)&lt;/P&gt;
&lt;P&gt;And network access is controlled through the 'source user' field in the security policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can use all 3 to achieve your objective &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 11:07:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187159#M56996</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-11-15T11:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Group Mapping vs Authentication Profile</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187160#M56997</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the Authentication Profile you select the specific users and groups that are allowed to authenticate with this profile. If you don’t add entries, no users can authenticate.&lt;/P&gt;
&lt;P&gt;In the mapping you can&lt;SPAN&gt;&amp;nbsp;control which groups are&amp;nbsp;retrieved from LDAP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope this clarifies the difference between the 2.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Cheers !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-Kiwi&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2017 11:12:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/group-mapping-vs-authentication-profile/m-p/187160#M56997</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-11-15T11:12:26Z</dc:date>
    </item>
  </channel>
</rss>

