User-ID Policies

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

User-ID Policies

L2 Linker

Hi,

 

I have a few questions regarding policies using user-id for access.

 

When I select add, to add a source user into a policy I can start typing a name and it will give me a list of users with thoses names to add in, like a prepopulation.

Is there a limit as to how many it will display?

for example, if i type the domain first it will give me a long list of users, but its clearly not the full domain users list? is this by design? can it be changed?

 

I'm also trying to add groups to make it alittle easier to read the rules and amalgamate single users, but it never prepopulates groups.

Even if I add ad groups manually this doesnt work, the rule denies access.

 

The authentication profile for the LDAP query is setup as default. I have viewed a video regarding using groups for policies, my configuration looks correct, so drawing a blank with this.

 

Kind Regards

Ian

3 REPLIES 3

Cyber Elite
Cyber Elite

hi @IanBroadway 

 

yes there's a limit to the number of items listed, this cannot be changed

 (because if you have a million objects the firewall needs to query it's database every time you add or delete a letter to repopulate the list)

 

for the groups: did you set up group mapping? this is a separate tab in the user identification configuration (device > user identification > group mapping), the authentication profile only provides authentication and a connector to the ldap for the group mapping profile

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

Hello,

Save your sanity and use groups. This will make it easier to add/remove users in the future and help the policies look cleaner.

 

Regards,

Thanks all

  • 2909 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!