- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-14-2024 07:10 AM
Hello
I am trying to achieve the following:
I would like to limit the groups the firewalls need to cache.
Therefore I would like to filter only to search below certain OUs in AD. As I learned this is not possible via LDAP Searchfilter with wildcards or sth.
Therefore I set up multiple LDAP Server Profiles where the Base DN matches the entry-OUs where I would like to search below and created multiple User ID Group Mappings without any search filters
I assumed this would allow the nested groups to be properly resolved to the users. Unfortunately this is not the case.
I think the problem might be the following:
Top-Level Group is a match for UID Group Mapping A
Below-Level Groups are match for UID Group Mapping B/C/D
During evaluation only the UID Group Mapping A is used further for evaluation and therefore doesn't find the users
Might this assumption be correct?
If so: Is it problematic for a firewall not to have filters and just ingest all AD groups or will that resolve in too much traffic (in an < 8k User AD with several hundrets of groups)
Thanks for any advice
03-14-2024 10:35 AM
Not using filters or the built-in group-include-list functionality isn't a problem as long as your platform(s) can sync the number of groups that you're requesting. So a PA-440 can only have 1,000 active groups used in policy, but a PA-5220 can have 10,000. If you only have hundreds of groups you shouldn't run into any issues even on the smallest platforms.
Nested groups will sync perfectly fine, but you need to insure that you're also syncing the membership of the nested group as well. So if I have a 'All-Devices' group as an example that has the nested 'All-Laptops', 'All-Desktops', and 'All-BYOD' as a simple example you need to sync the membership of those three nested groups to get things to function properly.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!