User-ID and child domain Global Catalog server

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

User-ID and child domain Global Catalog server

L1 Bithead

Hi,

 

I have a deployment question in regard to User-ID and multi domain.

 

If we are trying to pull group mappings and have user ID setup only on a child domain server through GC LDAP,  the user credentials used to login and thus pick up with the userid is in the format below.
- child.domain.com\user
- domain\user

I don't think it's possible to have two domain mapping for the same domain, this being as fqdn-domain-name/username (child.domain.com\user) and netbios/domain-name (domain\user)

But the end goal is to have both users mapped depending on how the user logs in.

 

Is this even possible? Internal discussions seem to agree that it is not possible.

If anyone has any input or what they could suggest as a better way, or if it can work like and how we do it? I would be greatful.

 

Currently running panos 7.1.6.

 

Regards,

Davyboy.

 

1 accepted solution

Accepted Solutions

L1 Bithead

With help from a colleague we resolved this issue. It actually can be done with a single LDAP profile using port 3268 for the GC server connection.

 

If you bind to port 389, even if you bind to a Global Catalog server, your search includes a single domain directory partition. If you bind to port 3268, your search includes all directory partitions in the forest. If the server you attempt to bind to over port 3268 is not a Global Catalog server, the server refuses the bind.

 

Davyboy.

View solution in original post

3 REPLIES 3

L7 Applicator

FYI, this topic was moved from Community Feedback to the General Topics area, as discussions about Palo Alto Networks products should not be in the Community Feedback area.

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!

L1 Bithead

With help from a colleague we resolved this issue. It actually can be done with a single LDAP profile using port 3268 for the GC server connection.

 

If you bind to port 389, even if you bind to a Global Catalog server, your search includes a single domain directory partition. If you bind to port 3268, your search includes all directory partitions in the forest. If the server you attempt to bind to over port 3268 is not a Global Catalog server, the server refuses the bind.

 

Davyboy.

Thanks. Limitation resolved after changing to port 3268

  • 1 accepted solution
  • 4578 Views
  • 3 replies
  • 2 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!