Hello, We are on PAN-OS 5.0.8 and use PA-5050, PA-5060, PA-200 (test boxes) and PA-3020's. We use the User-ID Agent running on VM servers. I have a couple questions, 1) When the PAN "loads" the group membership from our LDAP instance... we get the users that are part of the AD Groups we have "Group-Mapped"... Which is good and as expected. But if there are Groups 'nested' in an AD Group - they don't show up. Is there a way to get the 'nested' group members "loaded"? 2) Should Universal Groups work like Global Groups? Thanks for your time and help! Art
... View more