Group Mapping Nesting LDAP Filters

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Group Mapping Nesting LDAP Filters

L1 Bithead

Hello

I am trying to achieve the following:
I would like to limit the groups the firewalls need to cache.
Therefore I would like to filter only to search below certain OUs in AD. As I learned this is not possible via LDAP Searchfilter with wildcards or sth.

Therefore I set up multiple LDAP Server Profiles where the Base DN matches the entry-OUs where I would like to search below and created multiple User ID Group Mappings without any search filters

 

I assumed this would allow the nested groups to be properly resolved to the users. Unfortunately this is not the case.

I think the problem might be the following:

Top-Level Group is a match for UID Group Mapping A
Below-Level Groups are match for UID Group Mapping B/C/D
During evaluation only the UID Group Mapping A is used further for evaluation and therefore doesn't find the users

Might this assumption be correct?

 

If so: Is it problematic for a firewall not to have filters and just ingest all AD groups or will that resolve in too much traffic (in an < 8k User AD with several hundrets of groups)

 

Thanks for any advice

1 REPLY 1

Cyber Elite
Cyber Elite

@ipohlschneider ,

Not using filters or the built-in group-include-list functionality isn't a problem as long as your platform(s) can sync the number of groups that you're requesting. So a PA-440 can only have 1,000 active groups used in policy, but a PA-5220 can have 10,000. If you only have hundreds of groups you shouldn't run into any issues even on the smallest platforms.

 

Nested groups will sync perfectly fine, but you need to insure that you're also syncing the membership of the nested group as well. So if I have a 'All-Devices' group as an example that has the nested 'All-Laptops', 'All-Desktops', and 'All-BYOD' as a simple example you need to sync the membership of those three nested groups to get things to function properly. 

  • 1072 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!