<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PAN User-ID Agent in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-user-id-agent/m-p/520640#M554</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I installed User-ID Agent on the Windows DC, and it is working somewhat successfully. For some odd reason it recognizes the users from our domain but on the app's monitoring tab, where I can see the IP-User correlations, sometimes the users are identified like this:&lt;/P&gt;
&lt;P&gt;domain\user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and sometimes like this&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:user@domain.com" target="_blank"&gt;user@domain.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sometimes the latter converts to the first option sometimes not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I'm not sure how it actually works. I was logged in to my computer and I could see myself at the list of users on User-ID Agent but after a few minutes I disappeared - while i was logged in to my machine, and actively using it. So I might be missing something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Daniel&lt;/P&gt;</description>
    <pubDate>Tue, 08 Nov 2022 13:50:18 GMT</pubDate>
    <dc:creator>olloczky1</dc:creator>
    <dc:date>2022-11-08T13:50:18Z</dc:date>
    <item>
      <title>PAN User-ID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-user-id-agent/m-p/520640#M554</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I installed User-ID Agent on the Windows DC, and it is working somewhat successfully. For some odd reason it recognizes the users from our domain but on the app's monitoring tab, where I can see the IP-User correlations, sometimes the users are identified like this:&lt;/P&gt;
&lt;P&gt;domain\user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and sometimes like this&lt;/P&gt;
&lt;P&gt;&lt;A href="mailto:user@domain.com" target="_blank"&gt;user@domain.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sometimes the latter converts to the first option sometimes not.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I'm not sure how it actually works. I was logged in to my computer and I could see myself at the list of users on User-ID Agent but after a few minutes I disappeared - while i was logged in to my machine, and actively using it. So I might be missing something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 08 Nov 2022 13:50:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-user-id-agent/m-p/520640#M554</guid>
      <dc:creator>olloczky1</dc:creator>
      <dc:date>2022-11-08T13:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: PAN User-ID Agent</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-user-id-agent/m-p/522512#M622</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/256169"&gt;@olloczky1&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;This is most probably caused by who user credentials where sent to the AD for authentication. But if your domain is properly configured you don't have to worry. As explained here &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFnCAK" target="_blank"&gt;All about User-ID domain map - Knowledge Base - Palo Alto Networks&lt;/A&gt; FW is able to handle this and "normalize" the username and use single format. The link describe this is happening at the integrated user-id agent (on the firewall itself), but I suspect the User-ID agent application is doing it as well, before sending it to the firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should be able to check how FW receives user-ip mapping from the agent by looking at User-ID logs on the FW:&lt;/P&gt;
&lt;P&gt;Monitoring -&amp;gt; User-ID. There you can check the following columns (if not show by default you can add it)&lt;/P&gt;
&lt;P&gt;- User: this will be the username after normalization&lt;/P&gt;
&lt;P&gt;- User Provided by Source: self explanatory&lt;/P&gt;
&lt;P&gt;- Source Name: the source of the user-ip-mapping information.&lt;/P&gt;</description>
      <pubDate>Sun, 27 Nov 2022 21:33:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/pan-user-id-agent/m-p/522512#M622</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-11-27T21:33:07Z</dc:date>
    </item>
  </channel>
</rss>

