<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic USER_ID mapping constantly changing with Zscaler App in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-mapping-constantly-changing-with-zscaler-app/m-p/579756#M2778</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are facing an issue where PA user authenticated access from ZScaler app connect servers is failing intermittently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access through PA FW to a server network using user authentication is failing intermittently when connections are made from a pair of ZScaler app connector servers.&lt;/P&gt;
&lt;P&gt;CLI command "show user ip-user-mapping ip-address-of-ZPA" shows that the userid associated with the ZPA connectors is constantly changing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW logs do not show anything for the connections that are not completed successfully. The FW logs do report connections that fail the userid authentication rules, by logging unauthenticated access attempts with the last 'deny all' clean up rule of the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Successful connections are allowed &amp;amp; logged by the userid authentication rule, including the source user information.&lt;/P&gt;
&lt;P&gt;Server connections made from non-ZPA connectors, i.e. single user hosts, appear to be working successfully using the same userid authentication rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have latest 10.2.8 FW running and would like toc heck if anyone faced any similar issue or where can we check to see why this is happening.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="User-ID" id="User-ID"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Mar 2024 02:54:07 GMT</pubDate>
    <dc:creator>UtkarshKumar</dc:creator>
    <dc:date>2024-03-08T02:54:07Z</dc:date>
    <item>
      <title>USER_ID mapping constantly changing with Zscaler App</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-mapping-constantly-changing-with-zscaler-app/m-p/579756#M2778</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are facing an issue where PA user authenticated access from ZScaler app connect servers is failing intermittently.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Access through PA FW to a server network using user authentication is failing intermittently when connections are made from a pair of ZScaler app connector servers.&lt;/P&gt;
&lt;P&gt;CLI command "show user ip-user-mapping ip-address-of-ZPA" shows that the userid associated with the ZPA connectors is constantly changing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FW logs do not show anything for the connections that are not completed successfully. The FW logs do report connections that fail the userid authentication rules, by logging unauthenticated access attempts with the last 'deny all' clean up rule of the policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Successful connections are allowed &amp;amp; logged by the userid authentication rule, including the source user information.&lt;/P&gt;
&lt;P&gt;Server connections made from non-ZPA connectors, i.e. single user hosts, appear to be working successfully using the same userid authentication rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have latest 10.2.8 FW running and would like toc heck if anyone faced any similar issue or where can we check to see why this is happening.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;LI-PRODUCT title="User-ID" id="User-ID"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 02:54:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-mapping-constantly-changing-with-zscaler-app/m-p/579756#M2778</guid>
      <dc:creator>UtkarshKumar</dc:creator>
      <dc:date>2024-03-08T02:54:07Z</dc:date>
    </item>
  </channel>
</rss>

