A company is deploying User-ID in their network. The firewall team needs to have the ability to see and choose from a list of usernames and user groups directly inside the Panorama policies when creating new security rules.
How can this be achieved?
A company is deploying User-ID in their network. The firewall team needs to have the ability to see and choose from a list of usernames and user groups directly inside the Panorama policies when creating new security rules.
How can this be achieved?
To allow the firewall team to see and choose from a list of usernames and user groups directly inside the Panorama policies when creating new security rules, the correct approach is configuring the Master Device in Panorama > Device Groups. This configuration enables Panorama to use User-ID information from the designated master device, allowing the necessary visibility and selection capabilities within security policies.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG
For Panorama to use username or groups, its needs a master device set in the device group.
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG
B Master device for sure.
B is correct
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClIOCA0#:~:text=Configuring%20Group%20Mappings,a51e12a918ebc5e13df4fa789ea5f12b206b9b88618b27aae24c669a71415fa9
Its B, key word is ti be able to use in security polivy which is directly outlined in https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PMtpCAG
B. 100 percent!
Panorama > Device Groups, verified in PANOS 10.2x