cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who rated this post

Cyber Elite
Cyber Elite

Thank you @ChrisKarakostas for posting question.

 

To my knowledge it is not possible. In the security policy, you can use only AD Groups or Users.

Here is the link for Documentation: https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/map-users-to-groups.html You can configure the Base-DN in LDAP profile for entire AD Domain, however when you configure Group Mapping Setting only Group Objects and User Objects are available and this is what you will end up using as source user in a security policy.

 

If you are setting this up for the first time from scratch, below are a few KBs for reference:

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXWCA0

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClGOCA0

 

Note: After you complete the LDAP profile and Group Mapping Setting with user/group include list, you will have to commit it first before you can select user/group as a source in the security policy.

 

If you get stuck with the setup do not hesitate to post your problem here, I will do my best to help.

 

Kind Regards

Pavel

 

Help the community: Like helpful comments and mark solutions.

View solution in original post

Who rated this post