<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN-Agent Multi Domain and Group membership in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-multi-domain-and-group-membership/m-p/13472#M9875</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a forest domain with 2 child domains. Now I have 2 pan agents installed for both domains and it's working well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have the following problem about wich groups to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I must use 2 global groups to give users access through the firewall. A global Group from domain A and a Global Group from Domain B. So this means I must administer 2 groups in different domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally in AD when you use a Domain Local group then you can put users from different domains in this group.&lt;/P&gt;&lt;P&gt;I have done that so I have a Domain Local Group with users from Domain A and B and selected this group in the Policy but no success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to use a domain Local group witch the User-ID feature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The wish is to administer 1 group instead of 2 groups from both domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Osman Bor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 12 Mar 2010 12:48:14 GMT</pubDate>
    <dc:creator>u2343</dc:creator>
    <dc:date>2010-03-12T12:48:14Z</dc:date>
    <item>
      <title>PAN-Agent Multi Domain and Group membership</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-multi-domain-and-group-membership/m-p/13472#M9875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a forest domain with 2 child domains. Now I have 2 pan agents installed for both domains and it's working well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have the following problem about wich groups to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I must use 2 global groups to give users access through the firewall. A global Group from domain A and a Global Group from Domain B. So this means I must administer 2 groups in different domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally in AD when you use a Domain Local group then you can put users from different domains in this group.&lt;/P&gt;&lt;P&gt;I have done that so I have a Domain Local Group with users from Domain A and B and selected this group in the Policy but no success.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to use a domain Local group witch the User-ID feature?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The wish is to administer 1 group instead of 2 groups from both domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Osman Bor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Mar 2010 12:48:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-multi-domain-and-group-membership/m-p/13472#M9875</guid>
      <dc:creator>u2343</dc:creator>
      <dc:date>2010-03-12T12:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: PAN-Agent Multi Domain and Group membership</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-multi-domain-and-group-membership/m-p/13473#M9876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Osman,&lt;/P&gt;&lt;P&gt;we may read the users in the domain local group, but we will not create a user to ip mapping for the names that are not part of the domain that the pan agent is configured for.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So using the domain local group with not work as a work around for this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 18:06:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pan-agent-multi-domain-and-group-membership/m-p/13473#M9876</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-16T18:06:14Z</dc:date>
    </item>
  </channel>
</rss>

