- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
04-09-2020 02:27 AM
Hi,
I have a few questions regarding policies using user-id for access.
When I select add, to add a source user into a policy I can start typing a name and it will give me a list of users with thoses names to add in, like a prepopulation.
Is there a limit as to how many it will display?
for example, if i type the domain first it will give me a long list of users, but its clearly not the full domain users list? is this by design? can it be changed?
I'm also trying to add groups to make it alittle easier to read the rules and amalgamate single users, but it never prepopulates groups.
Even if I add ad groups manually this doesnt work, the rule denies access.
The authentication profile for the LDAP query is setup as default. I have viewed a video regarding using groups for policies, my configuration looks correct, so drawing a blank with this.
Kind Regards
Ian
04-09-2020 05:12 AM
hi @IanBroadway
yes there's a limit to the number of items listed, this cannot be changed
(because if you have a million objects the firewall needs to query it's database every time you add or delete a letter to repopulate the list)
for the groups: did you set up group mapping? this is a separate tab in the user identification configuration (device > user identification > group mapping), the authentication profile only provides authentication and a connector to the ldap for the group mapping profile
04-09-2020 02:27 PM
Hello,
Save your sanity and use groups. This will make it easier to add/remove users in the future and help the policies look cleaner.
Regards,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!