<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global Protect User ID not showing if connected to internal GW in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-id-not-showing-if-connected-to-internal-gw/m-p/598985#M5870</link>
    <description>&lt;P&gt;My company only uses the internal gateway detection to turn off gp, when connected to internally.&amp;nbsp; But in any case you should be able to detect the users with the user id agent, if you have it scan the logs of domain controller or a file/print server that everyone uses.&amp;nbsp; I'm not sure why global portect is not logging.&amp;nbsp; You might want to open a ticket, so support can see all the sensitive settings to determine why that isn't being logged.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also there is a privilege escalation vulnerability with 6.2.3 client and older 6.2 releases.&amp;nbsp; &lt;A href="https://www.tenable.com/cve/CVE-2024-5915" target="_blank"&gt;https://www.tenable.com/cve/CVE-2024-5915&lt;/A&gt; and&amp;nbsp;&lt;A href="https://security.paloaltonetworks.com/CVE-2024-5915" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-5915&lt;/A&gt;&amp;nbsp; 5.2 on CVSS v4, 7.8 on CVSS v3 and 6.8 on CVSS 2.0.&amp;nbsp; These different cve scales are clear as mud...&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 27 Sep 2024 14:48:32 GMT</pubDate>
    <dc:creator>JustinWoodman</dc:creator>
    <dc:date>2024-09-27T14:48:32Z</dc:date>
    <item>
      <title>Global Protect User ID not showing if connected to internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-id-not-showing-if-connected-to-internal-gw/m-p/598956#M5869</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;we have an issue that the User ID is not shown on the Palo if the GP Client is connected to the internal network.&lt;/P&gt;
&lt;P&gt;The detection is working but in the logs I can't see any user informations of internal connected clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For our Global Protect Clients we are using pre-auth.&lt;/P&gt;
&lt;P&gt;Settings for pre-auth and for the User Configs, both the same.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="smindorf_0-1727430224035.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62446iEA1C4C67B72B0E73/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="smindorf_0-1727430224035.png" alt="smindorf_0-1727430224035.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="smindorf_1-1727430278567.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62447i4C90D5DBC3136CBF/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="smindorf_1-1727430278567.png" alt="smindorf_1-1727430278567.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Authentification is against Active Directory.&lt;/P&gt;
&lt;P&gt;External we have no problem, all Rules are based on Active Directory groups and it is working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the User is internal Global Protect shows internal connection. But I can't see any user name in the Palo logs, but I can see connection informations like Username, Application...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I' hv also read docs like:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/best-practices/10-1/user-id-best-practices/user-id-best-practices/user-id-best-practices-for-globalprotect" target="_blank"&gt;User-ID Best Practices for GlobalProtect (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but it is not working. Maybe I missed some settings.&lt;/P&gt;
&lt;P&gt;On the LAN Zone, where the internal clients are connecting to is User ID enabled.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="smindorf_2-1727430625673.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/62448i8AB00889B934C8AA/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="smindorf_2-1727430625673.png" alt="smindorf_2-1727430625673.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Any hints where I can find a solution?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Palo Infos:&lt;/P&gt;
&lt;P&gt;Model PA-3260&lt;/P&gt;
&lt;P&gt;Software Version 10.2.11-h1&lt;/P&gt;
&lt;P&gt;GlobalProtect Agent 6.2.3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Sören&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 09:53:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-id-not-showing-if-connected-to-internal-gw/m-p/598956#M5869</guid>
      <dc:creator>smindorf</dc:creator>
      <dc:date>2024-09-27T09:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User ID not showing if connected to internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-id-not-showing-if-connected-to-internal-gw/m-p/598985#M5870</link>
      <description>&lt;P&gt;My company only uses the internal gateway detection to turn off gp, when connected to internally.&amp;nbsp; But in any case you should be able to detect the users with the user id agent, if you have it scan the logs of domain controller or a file/print server that everyone uses.&amp;nbsp; I'm not sure why global portect is not logging.&amp;nbsp; You might want to open a ticket, so support can see all the sensitive settings to determine why that isn't being logged.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also there is a privilege escalation vulnerability with 6.2.3 client and older 6.2 releases.&amp;nbsp; &lt;A href="https://www.tenable.com/cve/CVE-2024-5915" target="_blank"&gt;https://www.tenable.com/cve/CVE-2024-5915&lt;/A&gt; and&amp;nbsp;&lt;A href="https://security.paloaltonetworks.com/CVE-2024-5915" target="_blank"&gt;https://security.paloaltonetworks.com/CVE-2024-5915&lt;/A&gt;&amp;nbsp; 5.2 on CVSS v4, 7.8 on CVSS v3 and 6.8 on CVSS 2.0.&amp;nbsp; These different cve scales are clear as mud...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 14:48:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-id-not-showing-if-connected-to-internal-gw/m-p/598985#M5870</guid>
      <dc:creator>JustinWoodman</dc:creator>
      <dc:date>2024-09-27T14:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect User ID not showing if connected to internal GW</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-id-not-showing-if-connected-to-internal-gw/m-p/610026#M5983</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;we have updated all GP clients. Thanks for the hint.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Okay, I've opened a support Ticket and have discussed it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Solution:&lt;/P&gt;
&lt;P&gt;Add a Gateway on the Internal Interface, too and enable User-ID and minimal configuration.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you and Kind regards,&lt;/P&gt;
&lt;P&gt;Sören&amp;nbsp; Mindorf&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2024 14:48:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/global-protect-user-id-not-showing-if-connected-to-internal-gw/m-p/610026#M5983</guid>
      <dc:creator>smindorf</dc:creator>
      <dc:date>2024-10-21T14:48:47Z</dc:date>
    </item>
  </channel>
</rss>

