<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic radius user group in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/radius-user-group/m-p/391168#M90758</link>
    <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm studying the PCNSA, may I ask you a question about a security policy?&lt;/P&gt;&lt;P&gt;The "it" group in that policy could be a Radius group imported on the FW?&lt;/P&gt;&lt;P&gt;Or could be a way to map users to group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="group palo alto.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30341i0F0D54BD99D27AC7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="group palo alto.png" alt="group palo alto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;it would be very useful if Palo Alto offered a free VM lab to test which we are learning, anyone know if it's already been provided?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Ale&lt;/P&gt;</description>
    <pubDate>Sun, 14 Mar 2021 21:38:22 GMT</pubDate>
    <dc:creator>alessandroco</dc:creator>
    <dc:date>2021-03-14T21:38:22Z</dc:date>
    <item>
      <title>radius user group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-user-group/m-p/391168#M90758</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm studying the PCNSA, may I ask you a question about a security policy?&lt;/P&gt;&lt;P&gt;The "it" group in that policy could be a Radius group imported on the FW?&lt;/P&gt;&lt;P&gt;Or could be a way to map users to group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="group palo alto.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/30341i0F0D54BD99D27AC7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="group palo alto.png" alt="group palo alto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;it would be very useful if Palo Alto offered a free VM lab to test which we are learning, anyone know if it's already been provided?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;Ale&lt;/P&gt;</description>
      <pubDate>Sun, 14 Mar 2021 21:38:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-user-group/m-p/391168#M90758</guid>
      <dc:creator>alessandroco</dc:creator>
      <dc:date>2021-03-14T21:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: radius user group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-user-group/m-p/391422#M90776</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/175011"&gt;@alessandroco&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are two ways to use users and user groups in policy:&lt;/P&gt;&lt;P&gt;- Local database: You can create the users (username and password) localy on firewall and then create user group again localy. After that in your security rule you can refer indivituals local users or the local user group. Local users and groups are configured under Device -&amp;gt; Local Users Database&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Group Mapping: Unfortunately currently only LDAP is supported. So if you have Active Directory, firewall will use LDAP to query the AD and "extract" all user groups that you have already created at the AD (you can set some filters and limit the groups that firewall will query, but by default FW will try to collect them all).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to anwert your question - No, user groups information cannot be collected over RADIUS. You need LDAP to gather group membership information (which user is member of which group).&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 11:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-user-group/m-p/391422#M90776</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2021-03-16T11:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: radius user group</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/radius-user-group/m-p/391528#M90785</link>
      <description>Hello! Thank you very much for your answer, now is more clear to me!&lt;BR /&gt;&lt;BR /&gt;Bwt I still need a clarification, in fact the question said: “what is the&lt;BR /&gt;purpose of the group in the security policy rule?&lt;BR /&gt;&lt;BR /&gt;1)map username to groups&lt;BR /&gt;2)that group is a radius group&lt;BR /&gt;&lt;BR /&gt;Which one do you suggest?&lt;BR /&gt;&lt;BR /&gt;Thank you very much!&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Mar 2021 16:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/radius-user-group/m-p/391528#M90785</guid>
      <dc:creator>alessandroco</dc:creator>
      <dc:date>2021-03-16T16:23:44Z</dc:date>
    </item>
  </channel>
</rss>

