To configure group mapping on a Palo Alto Networks firewall, follow these steps in order:
Navigate to Device > User Identification > Group Mapping:
This is the initial step where you access the group mapping settings in the web interface.
Add a new group mapping:
After navigating to the group mapping section, the next step is to add a new group mapping configuration.
Enter a unique name to identify the group mapping configuration:
Provide a unique and descriptive name for the new group mapping configuration to easily identify it.
Create an LDAP Server Profile:
This step involves creating an LDAP Server Profile, which defines the connection settings for the LDAP server that will be queried for user and group information.
Select the LDAP Server Profile:
Finally, associate the created LDAP Server Profile with the group mapping configuration. This links the group mapping to the specific LDAP server.
Order in Process:
Navigate to Device > User Identification > Group Mapping
Add a new group mapping.
Enter a unique name to identify the group mapping configuration.
Create an LDAP Server Profile.
Select the LDAP Server Profile.
References:
Palo Alto Networks - Configuring Group Mapping: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/user-id/map-users-to-groups
Palo Alto Networks - User-ID Agent and Group Mapping Configuration: https://knowledgebase.paloaltonetworks.com
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit