05-02-2012 03:20 AM
Hello,
I have Two FOREST A and B, I have a trust relation between this two forest.
When I add a user of the forest A in the group (local) of the forest B I can't see in the pan agent the users.
Any Idea to see the user of the forest A in the group of the forest B?
regards,
05-02-2012 12:40 PM
Update to my post below:
Since I only had 3 users from a remote forest to worry about I was successful by adding their remotedomain\username logon IDs to the SourceUser list in one of our policies. It seems that although the agent won't expand the groups, the FireWall is quite happy when you explicitly list user's names in the policy.
----------------------------
I was trying to make this work just this morning also - same result. Users from another domain are not seen although their names do appear on the Monitor page next to their blocked packets.
I think the answer to y/our question is posted here:
https://live.paloaltonetworks.com/message/1819#1819
I guess we'll have to create a separate policy and filter based on PC names rather than user names. It won't be pretty though.
PaloAlto - why is it hard to expand Domain Local group membership?
05-03-2012 05:03 AM
Hi Skytrain,
I have seen that is not possible to use multiforest with the PAN-AGENT 3.1.2. So I do an update of PANOS in 4.1.6
and an update pan-agent (user-id-agent) 4.1.4.
Moreover you must use the FIREWALL for enumeration and not the user-id-agent because you must use the global catalogue to see the
forest.
I v seen to that the group must be an Universal Group.
I do an another test but without success for the moment!
regards,
05-03-2012 11:10 AM
I think you can select ldap-proxy when you setup your userid connection to make the firewall query the ldap through your userid agent (as before) instead of having to do ldap on its own (regarding flows in your network).
05-03-2012 11:20 AM
Hello mikand,
it's true that you can use the option ldap-proxy. but if you want browse the global catalogue (port 3268) and not LDAP
(port 389) you must use the firewall ldap server configuration. the global is usefull when you have severals domains.
And when I do a test with two different forest with trusted domain the enumeration doesn't work( I see just the main domain). Maybe it's only possible with severals domain in the same forest?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!