Panorama GROUP MAPPING - How to show AD groups in Panorama policies

Поделиться
HTML-код
  • Опубликовано: 2 ноя 2024

Комментарии • 26

  • @netsums
    @netsums  7 месяцев назад

    🔥 Join our exclusive online training: "Mastering Palo Alto Firewalls: Comprehensive Training in Operation and Management." 🚀 Prepare confidently for the PCNSA exam with expert guidance and hands-on exercises. Reserve your spot now and benefit from Early Bird discounts and bonusses! 💻 Learn more and register at netsums.com/training

  • @TimYamamoto-or1id
    @TimYamamoto-or1id 6 месяцев назад +1

    Can't thank-you enough...your clear instructions make this a breeze....

    • @netsums
      @netsums  6 месяцев назад

      You're welcome, I'm glad you could get some value from the video. :-)

  • @nfreddyyy
    @nfreddyyy Год назад

    You are a legend my friend. Love it! Please keep up the good work and your happy self 😁

    • @netsums
      @netsums  Год назад

      Thank you so much for the nice comment! I'm glad you liked the video. :-)

  • @highsteppersconsultant590
    @highsteppersconsultant590 10 месяцев назад

    Very direct and straightforward...thanks

    • @netsums
      @netsums  10 месяцев назад

      I'm happy you liked the video. :)

  • @lifequestions5546
    @lifequestions5546 Год назад

    Thank you. It helps to refresh the knowledge.

    • @netsums
      @netsums  Год назад

      You are welcome. Thank you for the comment. :-)

  • @潘群崴
    @潘群崴 Месяц назад

    Hello, Admin. Following your configuration, I've set up LDAP, and the policy configuration works fine. However, the traffic and User ID are showing users instead of groups. Could it be because the User ID Agent is installed, preventing the display of groups?

    • @netsums
      @netsums  Месяц назад +1

      Groups are not displayed in the traffic logs, only users. In order to know if a user is member of a set of groups, you need to go to the CLI and enter the commands "show user user-ids all", or "show user group name "

    • @潘群崴
      @潘群崴 Месяц назад

      @@netsums Thank you, Admin, for your response. I appreciate your hard work.😀

    • @潘群崴
      @潘群崴 Месяц назад

      @@netsums I apologize, but may I ask you one more question? If LDAP is configured on Palo Alto, will the User ID Agent also retrieve the information?

    • @netsums
      @netsums  Месяц назад +1

      LDAP is used for authentication and group mapping. The user ID agent does the mapping from an IP address to a username. They do different things.

    • @潘群崴
      @潘群崴 Месяц назад

      @@netsums Hi, Admin, sorry to bother you. May I ask if you know how to set up the Terminal Server Agent? Is it the same method as setting up the User ID Agent?

  • @FunbySon
    @FunbySon Месяц назад +1

    Create some video on dynamic group

  • @TsH18
    @TsH18 6 месяцев назад

    in my case that wasn't enough.... i had to enable "Enable reporting and filtering on groups" under Panorama > Setup > Management > Panorama Settings and "Store users and groups from the master device if reporting and filtering of groups is enabled in Panorama settings" under Panorama > Device Groups >

    • @netsums
      @netsums  6 месяцев назад

      Okay, I didn't have to enable these options in my lab. But thanks letting us know! ! Probably you will be able to help other people. :-) What version are you running?

    • @TsH18
      @TsH18 6 месяцев назад

      @@netsums the version is 10.1.11-h5

    • @jonreyno1187
      @jonreyno1187 4 месяца назад

      Awesome, for me was the same, thanks

    • @alejandrorodriguez3771
      @alejandrorodriguez3771 2 месяца назад

      @@netsums the problem was that you configured LDAP and user ID mapping on panorama, under the specific template, pushed to the fw, and then you try to create a rule in the fw itself (it is show in the video that you are in the FW, not in panorama), and that is why you see the groups there, Try to create a sec rule from panorama, you will no see the groups
      I had to enable "Enable reporting and filtering on groups" under Panorama > Setup > Management > Panorama Settings and "Store users and groups from the master device if reporting and filtering of groups is enabled in Panorama settings" under Panorama > Device Groups >

    • @netsums
      @netsums  2 месяца назад

      The video is a little old, but I took a look at it again. On minute 6:21 I start adding a new security rule in Panorama, and it does show the Active Directory groups. That's what you meant, right? Or did I misunderstand the problem? :-)

  • @sridharbvnl2101
    @sridharbvnl2101 10 месяцев назад

    excellent

    • @netsums
      @netsums  10 месяцев назад

      Thank you, I'm glad you liked it

  • @netsums
    @netsums  8 месяцев назад

    FREE Palo Alto Cheat Sheet in different formats and further FREE resources: netsums.com/resources