<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic traffic log did not display user information in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/591782#M3406</link>
    <description>&lt;P&gt;The customer uses GP to dial in and adopts LDAP authentication method.&lt;BR /&gt;After the customer dialed in normally, they accessed internal resources, but the source user colums in the traffic log did not display user information, which was normal before. The customer did not make any other changes, and the user id in the area was also checked.&lt;BR /&gt;How to investigate and what suggestions do you have。&lt;/P&gt;
&lt;P&gt;or ：&lt;SPAN data-slate-fragment="JTVCJTdCJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmNoaWxkcmVuJTIyJTNBJTVCJTdCJTIyaWQlMjIlM0ElMjJlNm5iMHBuYXBlJTIyJTJDJTIycGFyYUlkeCUyMiUzQTMlMkMlMjJzcmMlMjIlM0ElMjIlRTYlODglOTYlRTglODAlODVkZWJ1ZyUyMHNvZnR3YXJlJTIwcmVzdGFydCUyMHByb2Nlc3MlMjB1c2VyLWlkJTIyJTJDJTIyZHN0JTIyJTNBJTIyT3IlMjBkZWJ1ZyUyMHNvZnR3YXJlJTIwcmVzdGFydCUyMHByb2Nlc3MlMjB1c2VyJTIwaWQlMjIlMkMlMjJtZXRhZGF0YSUyMiUzQSUyMiUyMiUyQyUyMm1ldGFEYXRhJTIyJTNBJTVCJTVEJTJDJTIydGV4dCUyMiUzQSUyMmRlYnVnJTIwc29mdHdhcmUlMjByZXN0YXJ0JTIwcHJvY2VzcyUyMHVzZXItaWQlMjIlN0QlNUQlN0QlNUQ="&gt;debug software restart process user-id ？&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic log.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60760i8C0A5C99D98B47ED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic log.png" alt="traffic log.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="user-information.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60761iC75D828D7C922317/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="user-information.png" alt="user-information.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 12 Jul 2024 04:06:31 GMT</pubDate>
    <dc:creator>Felixcao</dc:creator>
    <dc:date>2024-07-12T04:06:31Z</dc:date>
    <item>
      <title>traffic log did not display user information</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/591782#M3406</link>
      <description>&lt;P&gt;The customer uses GP to dial in and adopts LDAP authentication method.&lt;BR /&gt;After the customer dialed in normally, they accessed internal resources, but the source user colums in the traffic log did not display user information, which was normal before. The customer did not make any other changes, and the user id in the area was also checked.&lt;BR /&gt;How to investigate and what suggestions do you have。&lt;/P&gt;
&lt;P&gt;or ：&lt;SPAN data-slate-fragment="JTVCJTdCJTIydHlwZSUyMiUzQSUyMnBhcmFncmFwaCUyMiUyQyUyMmNoaWxkcmVuJTIyJTNBJTVCJTdCJTIyaWQlMjIlM0ElMjJlNm5iMHBuYXBlJTIyJTJDJTIycGFyYUlkeCUyMiUzQTMlMkMlMjJzcmMlMjIlM0ElMjIlRTYlODglOTYlRTglODAlODVkZWJ1ZyUyMHNvZnR3YXJlJTIwcmVzdGFydCUyMHByb2Nlc3MlMjB1c2VyLWlkJTIyJTJDJTIyZHN0JTIyJTNBJTIyT3IlMjBkZWJ1ZyUyMHNvZnR3YXJlJTIwcmVzdGFydCUyMHByb2Nlc3MlMjB1c2VyJTIwaWQlMjIlMkMlMjJtZXRhZGF0YSUyMiUzQSUyMiUyMiUyQyUyMm1ldGFEYXRhJTIyJTNBJTVCJTVEJTJDJTIydGV4dCUyMiUzQSUyMmRlYnVnJTIwc29mdHdhcmUlMjByZXN0YXJ0JTIwcHJvY2VzcyUyMHVzZXItaWQlMjIlN0QlNUQlN0QlNUQ="&gt;debug software restart process user-id ？&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="traffic log.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60760i8C0A5C99D98B47ED/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="traffic log.png" alt="traffic log.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="user-information.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60761iC75D828D7C922317/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="user-information.png" alt="user-information.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 04:06:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/591782#M3406</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2024-07-12T04:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: traffic log did not display user information</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/591832#M3407</link>
      <description>&lt;P&gt;typically there's 2 reasons this could happen:&lt;/P&gt;
&lt;P&gt;- The zone that is used for the GP gateway tunnel interface does not have user-id enabled&lt;/P&gt;
&lt;P&gt;- userid agent (or agentless) does not have an exclude for the GlobalProtect IP pool and is trying to refresh mapping from AD logs (which may or may not be there dependiong on what the user is doing). add an exclude for the IP pool should fix this issue&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 09:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/591832#M3407</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-07-12T09:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: traffic log did not display user information</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/591902#M3408</link>
      <description>&lt;P&gt;hi cyber elite:&lt;/P&gt;
&lt;P&gt;thanks you reply&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;typically there's 2 reasons this could happen:&lt;/P&gt;
&lt;P&gt;- The zone that is used for the GP gateway tunnel interface does not have user-id enabled&lt;/P&gt;
&lt;P&gt;i confirm the zone that is used for the GP gateway tunnel interface have user-id enabled&lt;/P&gt;
&lt;P&gt;- userid agent (or agentless) does not have an exclude for the GlobalProtect IP pool and is trying to refresh mapping from AD logs (which may or may not be there dependiong on what the user is doing). add an exclude for the IP pool should fix this issue&lt;/P&gt;
&lt;P&gt;i don't understant it ,how to exclude for the ip pool fix this issue. ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 14 Jul 2024 10:51:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/591902#M3408</guid>
      <dc:creator>Felixcao</dc:creator>
      <dc:date>2024-07-14T10:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: traffic log did not display user information</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/592404#M3430</link>
      <description>&lt;P&gt;the exclude will help prevent conflicts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;GlobalProtect automatically teaches the firewall all the correct user-ids.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;adding another user-id method for that subnet can only introduce complications&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 08:29:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/traffic-log-did-not-display-user-information/m-p/592404#M3430</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2024-07-18T08:29:06Z</dc:date>
    </item>
  </channel>
</rss>

