PAN AGENT WITH MULTI-FOREST

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PAN AGENT WITH MULTI-FOREST

L3 Networker

Hello,

I have Two FOREST A and B, I have a trust relation between this two forest.

When I add a user of the forest A in the group (local) of the forest B I can't see in the pan agent the users.

Any Idea to see the user of the forest A in the group of the forest B?

regards,

12 REPLIES 12

L1 Bithead

Update to my post below:

Since I only had 3 users from a remote forest to worry about I was successful by adding their remotedomain\username logon IDs to the SourceUser list in one of our policies. It seems that although the agent won't expand the groups, the FireWall is quite happy when you explicitly list user's names in the policy.

----------------------------

I was trying to make this work just this morning also - same result. Users from another domain are not seen although their names do appear on the Monitor page next to their blocked packets.

I think the answer to y/our question is posted here:

https://live.paloaltonetworks.com/message/1819#1819

I guess we'll have to create a separate policy and filter based on PC names rather than user names. It won't be pretty though.

PaloAlto - why is it hard to expand Domain Local group membership?

Hi Skytrain,

I have seen that is not possible to use multiforest with the PAN-AGENT 3.1.2. So I do an update of PANOS in 4.1.6

and an update pan-agent (user-id-agent) 4.1.4.

Moreover you must use the FIREWALL for enumeration and not the user-id-agent because you must use the global catalogue to see the

forest.

I v seen to that the group must be an Universal Group.

I do an another test but without success for the moment!

regards,

I think you can select ldap-proxy when you setup your userid connection to make the firewall query the ldap through your userid agent (as before) instead of having to do ldap on its own (regarding flows in your network).

Hello mikand,

it's true that you can use the option ldap-proxy. but if you want browse the global catalogue (port 3268) and not LDAP

(port 389) you must use the firewall ldap server configuration. the global is usefull when you have severals domains.

And when I do a test with two different forest with trusted domain the enumeration doesn't work( I see just the main domain). Maybe it's only possible with severals domain in the same forest?

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!