cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this solution

Hi @AProwant 

Unfortunately I don't have personal experiance (hope one day to have the same in our environment), but I believe you need the following:

- You need Group Mapping with enabled "Fetch list of managed devices". This will tell the firewall to pull the serial number of AD computers over LDAP - https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-server-profiles...

- Create HIP object that as "Managed" set you "yes under General Tab -> Host Info

 

Once you enable fetching device list in group mapping you should be able to see the list of retrieved devices with:

> show user ldap-device-serialno all

If you don't see it either:

- the service account you use for the LDAP doesn't have enough permissions

- The serial number is not set as attribute for the computer objects in the AD - https://www.reddit.com/r/paloaltonetworks/comments/n1pe2p/global_protect_hip_check_machine_account_e...

View solution in original post

Who Me Too'd this solution