- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-06-2017 05:54 PM
I see history here indicating the user-id agent has been blind to computer names when the group membership is added to user IDs. The CLI DOES show the computer name as a userID (with a post-pended $) and the groups are mapped correctly to the computer group I created and dumped the computer in.
On the other hand the USER signed into that computer does not show the computer group as one of their member groups.
It looks like the base data is in the firewall but I can't get traffic or security policies to recognize the traffic from the computer name, only the AD user name.
Is there some way I can introduce computer names and/or computer groups into user-id based enforcement? My goal is to create a few policies based on AD computer group. Maybe custom AD groups in the Group Mappings Settings?
03-08-2017 06:46 AM
Correct as of 7.1 and lower. There's no way I know of to enumerate computer groups and apply them to a "source" or "dest" for security policy.
03-07-2017 07:35 AM - edited 03-07-2017 07:37 AM
At my company we make use of EDLs to accomplish.
We built a script which scrubs the AD groups we want. We then bump that script againts DNS. That DNS output is dumped into a text file on our internal network which is hosted behind IIS. We then target the Palo to that .txt file and leverage that object in the firewall for security policy controls.
This process is cumbersome for sure, but works for us.
03-07-2017 06:08 PM
Brandon, thanks for the reply. I'm guessing that the pain you go through to harvest this data is a result of not having a palo-alto supported solution to this? Does anyone else have alternatives? Something in PANOS 8 maybe?
03-08-2017 06:46 AM
Correct as of 7.1 and lower. There's no way I know of to enumerate computer groups and apply them to a "source" or "dest" for security policy.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!