- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-08-2022 03:01 AM
Hi @AProwant
Unfortunately I don't have personal experiance (hope one day to have the same in our environment), but I believe you need the following:
- You need Group Mapping with enabled "Fetch list of managed devices". This will tell the firewall to pull the serial number of AD computers over LDAP - https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-web-interface-help/device/device-server-profiles...
- Create HIP object that as "Managed" set you "yes under General Tab -> Host Info
Once you enable fetching device list in group mapping you should be able to see the list of retrieved devices with:
> show user ldap-device-serialno all
If you don't see it either:
- the service account you use for the LDAP doesn't have enough permissions
- The serial number is not set as attribute for the computer objects in the AD - https://www.reddit.com/r/paloaltonetworks/comments/n1pe2p/global_protect_hip_check_machine_account_e...