So it appears that UserID requires something more to apply to multiple rules. I see conversations from 2019 posts that have no real answers. I need to apply a UserID group pulled via LDAP across 5000 rules. Expedition shows the full LDAP name that I added to a rule in Panorama which is fine but I can do nothing with that information. I cannot copy, paste, edit this at all. This appears broken. Is there an API requirement or a direct device link that needs to happen?
No, maybe I didn't correctly state it. I am talking about Source User in Security Policies. That is pulled via Group Mapping which relies on a LDAP server profile. In Expedition it shows the full LDAP bind for the group I want. I can do nothing with that in Expedition. I cannot change it and I cannot apply that entry to additional rules
When you are in Expedition and have imported Panorama configuration, under Objects there is a section for Users. In there a Users via API and a User Groups via API. Neither of these are actually part of a regular Panorama configuration from what I can tell. This may be what I need but I don't know that there's anything explaining this.
Generally those UserID groups are created once you have tied the panorama device into LDAP so it can pull in those UserID groups from what you have created, I would not recommend migrating this from within expedition itself. Although yes the field does exist it would make more sense to make these changes from within Panorama to isolate East-West traffic based off of UserID.
Sorry maybe I was not clear, I am saying that those UserID groups should be first created on the firewall then imported into Expedition. Now from within expedition once you have imported them in you can simply multi-edit the policies to incorporate them into your policies, but I would not attempt to create these UserID modifications from within expedition since they are not tied back to LDAP and able to pull down that type of information. Once this is done yes you should be able to push those changes via API.
Yes, I see that but you cannot select any of the existing groups or users from your rules in that dropdown. You also cannot manually add a user or group. So for rules that I have already selected the user or group from Group mapping in Panorama, it shows the full LDAP bind but you can't edit/change or copy to another rule.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!