Create custom groups based
on LDAP filters so that you can base firewall policies on user attributes
that don’t match existing user groups in the LDAP directory. The
User-ID service maps all the LDAP directory users who match the
filter to the custom group. If you create a custom group with the
same Distinguished Name (DN) as an existing Active Directory group
domain name, the firewall uses the custom group in all references
to that name (for example, in policies and logs). To create a custom
group, Add and configure the following fields: Name—Enter a custom group name that
is unique in the group mapping configuration for the current firewall
or virtual system. LDAP Filter—Enter a filter of up to 2,048
characters.
Use only indexed
attributes in the filter to expedite LDAP searches and minimize
the performance impact on the LDAP directory server; the firewall
does not validate LDAP filters.
The combined maximum
for the Included Groups and Custom
Group lists is 640 entries. To delete a custom
group, select and Delete it. To make a copy
of a custom group, select and Clone it and
then edit the fields as appropriate.
After
adding or cloning a custom group, you must Commit your changes
before your new custom group is available in policies and objects.
|