<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-id ip mapping issue in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-ip-mapping-issue/m-p/594695#M3573</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;my customer having problem with user-id&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am trying to solve this issue but not working, so I need help&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Customer divice pa-3410 panOS10.2.9 connection with microsoft Active-directory 2012R2(not sure)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Its agenteless user-id, winrm http, ldap and keberos connection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;for example VPN user(3rdParty vpn) get Auth from AD with SSO (fri/k-yunsw) &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Local user get auth from AD with (fri/yunsw) both user same person but they has different IP(different zone, vpn user has no group on AD server, local user has group on AD server)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If fri/yunsun loged in as local user some times PA reconiging as a local user(user-id log fri/yunsun, its correct.) but, traffic monitor says fri/k-yunsw, so the traffic has denied.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After then I ignore user 'fri/k-*'(add ignore user list) but still PA monitor log says 'fri/k-xxx user dinied'.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I checked cli&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;'show user ip-user-mapping all | fri/k-'&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; not poped up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin@NGFW&amp;gt; show log userid | match k-yunsw&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; not poped up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin@NGFW&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3, there is only fri\yunsw &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;8...skipping...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;985,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 11:37:22,1,0x80000000,fri\yunsw,,2024-08-09T11:37:32.551+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 12:49:49,024101008522,USERID,login,2562,2024/08/09 12:49:49,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7187,0,0,active-directory,,7362383078554855078,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 12:49:36,1,0x80000000,fri\yunsw,,2024-08-09T12:49:49.974+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 13:19:05,024101008522,USERID,login,2562,2024/08/09 13:19:05,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7187,0,0,active-directory,,7362383078554861902,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 13:18:52,1,0x80000000,fri\yunsw,,2024-08-09T13:19:05.627+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 14:04:50,024101008522,USERID,login,2562,2024/08/09 14:04:50,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7189,0,0,active-directory,,7362383078554872019,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 14:04:39,1,0x80000000,fri\yunsw,,2024-08-09T14:04:50.485+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 14:48:49,024101008522,USERID,login,2562,2024/08/09 14:48:49,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7186,0,0,active-directory,,7362383078554882345,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 14:48:36,1,0x80000000,fri\yunsw,,2024-08-09T14:48:50.029+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 15:25:53,024101008522,USERID,login,2562,2024/08/09 15:25:53,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7190,0,0,active-directory,,7362383078554890596,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 15:25:44,1,0x80000000,fri\yunsw,,2024-08-09T15:25:54.339+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 15:37:10,024101008522,USERID,login,2562,2024/08/09 15:37:10,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7186,0,0,active-directory,,7362383078554892997,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 15:36:56,1,0x80000000,fri\yunsw,,2024-08-09T15:37:10.937+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 15:44:54,024101008522,USERID,login,2562,2024/08/09 15:44:54,vsys2,172.25.20.141,fri\yunsw,pdc.fri.kr,0,1,7176,0,0,active-directory,,7362383078554894785,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 15:44:30,1,0x80000000,fri\yunsw,,2024-08-09T15:44:54.764+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:07:56,024101008522,USERID,login,2562,2024/08/09 16:07:56,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7188,0,0,active-directory,,7362383078554899688,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:07:44,1,0x80000000,fri\yunsw,,2024-08-09T16:07:56.830+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:16:47,024101008522,USERID,login,2562,2024/08/09 16:16:47,vsys2,172.25.20.141,fri\yunsw,pdc.fri.kr,0,1,7179,0,0,active-directory,,7362383078554901455,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:16:27,1,0x80000000,fri\yunsw,,2024-08-09T16:16:48.197+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:27:11,024101008522,USERID,login,2562,2024/08/09 16:27:11,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7191,0,0,active-directory,,7362383078554904535,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:27:02,1,0x80000000,fri\yunsw,,2024-08-09T16:27:11.922+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:47:43,024101008522,USERID,login,2562,2024/08/09 16:47:43,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7200,0,0,active-directory,,7362383078554912869,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:47:44,1,0x80000000,fri\yunsw,,2024-08-09T16:47:44.058+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin@NGFW&amp;gt; GGGGGG&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A few days later I checked 'Enable Server Session Read' but Customer says still not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;any idea??&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Aug 2024 09:35:22 GMT</pubDate>
    <dc:creator>JoDongWook</dc:creator>
    <dc:date>2024-08-13T09:35:22Z</dc:date>
    <item>
      <title>User-id ip mapping issue</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-ip-mapping-issue/m-p/594695#M3573</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi all&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;my customer having problem with user-id&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I am trying to solve this issue but not working, so I need help&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Customer divice pa-3410 panOS10.2.9 connection with microsoft Active-directory 2012R2(not sure)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Its agenteless user-id, winrm http, ldap and keberos connection.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;for example VPN user(3rdParty vpn) get Auth from AD with SSO (fri/k-yunsw) &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Local user get auth from AD with (fri/yunsw) both user same person but they has different IP(different zone, vpn user has no group on AD server, local user has group on AD server)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If fri/yunsun loged in as local user some times PA reconiging as a local user(user-id log fri/yunsun, its correct.) but, traffic monitor says fri/k-yunsw, so the traffic has denied.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After then I ignore user 'fri/k-*'(add ignore user list) but still PA monitor log says 'fri/k-xxx user dinied'.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I checked cli&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;'show user ip-user-mapping all | fri/k-'&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; not poped up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin@NGFW&amp;gt; show log userid | match k-yunsw&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; not poped up&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin@NGFW&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3, there is only fri\yunsw &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;8...skipping...&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;985,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 11:37:22,1,0x80000000,fri\yunsw,,2024-08-09T11:37:32.551+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 12:49:49,024101008522,USERID,login,2562,2024/08/09 12:49:49,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7187,0,0,active-directory,,7362383078554855078,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 12:49:36,1,0x80000000,fri\yunsw,,2024-08-09T12:49:49.974+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 13:19:05,024101008522,USERID,login,2562,2024/08/09 13:19:05,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7187,0,0,active-directory,,7362383078554861902,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 13:18:52,1,0x80000000,fri\yunsw,,2024-08-09T13:19:05.627+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 14:04:50,024101008522,USERID,login,2562,2024/08/09 14:04:50,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7189,0,0,active-directory,,7362383078554872019,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 14:04:39,1,0x80000000,fri\yunsw,,2024-08-09T14:04:50.485+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 14:48:49,024101008522,USERID,login,2562,2024/08/09 14:48:49,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7186,0,0,active-directory,,7362383078554882345,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 14:48:36,1,0x80000000,fri\yunsw,,2024-08-09T14:48:50.029+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 15:25:53,024101008522,USERID,login,2562,2024/08/09 15:25:53,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7190,0,0,active-directory,,7362383078554890596,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 15:25:44,1,0x80000000,fri\yunsw,,2024-08-09T15:25:54.339+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 15:37:10,024101008522,USERID,login,2562,2024/08/09 15:37:10,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7186,0,0,active-directory,,7362383078554892997,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 15:36:56,1,0x80000000,fri\yunsw,,2024-08-09T15:37:10.937+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 15:44:54,024101008522,USERID,login,2562,2024/08/09 15:44:54,vsys2,172.25.20.141,fri\yunsw,pdc.fri.kr,0,1,7176,0,0,active-directory,,7362383078554894785,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 15:44:30,1,0x80000000,fri\yunsw,,2024-08-09T15:44:54.764+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:07:56,024101008522,USERID,login,2562,2024/08/09 16:07:56,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7188,0,0,active-directory,,7362383078554899688,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:07:44,1,0x80000000,fri\yunsw,,2024-08-09T16:07:56.830+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:16:47,024101008522,USERID,login,2562,2024/08/09 16:16:47,vsys2,172.25.20.141,fri\yunsw,pdc.fri.kr,0,1,7179,0,0,active-directory,,7362383078554901455,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:16:27,1,0x80000000,fri\yunsw,,2024-08-09T16:16:48.197+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:27:11,024101008522,USERID,login,2562,2024/08/09 16:27:11,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7191,0,0,active-directory,,7362383078554904535,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:27:02,1,0x80000000,fri\yunsw,,2024-08-09T16:27:11.922+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1,2024/08/09 16:47:43,024101008522,USERID,login,2562,2024/08/09 16:47:43,vsys2,172.25.20.141,fri\yunsw,tdc.fri.kr,0,1,7200,0,0,active-directory,,7362383078554912869,0x0,0,0,0,0,NGFW-USER,NGFW,2,,2024/08/09 16:47:44,1,0x80000000,fri\yunsw,,2024-08-09T16:47:44.058+09:00&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;admin@NGFW&amp;gt; GGGGGG&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A few days later I checked 'Enable Server Session Read' but Customer says still not working.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;any idea??&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2024 09:35:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/user-id-ip-mapping-issue/m-p/594695#M3573</guid>
      <dc:creator>JoDongWook</dc:creator>
      <dc:date>2024-08-13T09:35:22Z</dc:date>
    </item>
  </channel>
</rss>

