<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Activeync, iislogs and user-id in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50340#M1137</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not seeing any events 4624 on Exchange.&amp;nbsp; I have enabled auditing via GPO for a number of items on the server and still nothing.&amp;nbsp; I am seeing some 4624s on the DCs, but no reference to the Ipad IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jan 2013 22:45:49 GMT</pubDate>
    <dc:creator>BobW</dc:creator>
    <dc:date>2013-01-15T22:45:49Z</dc:date>
    <item>
      <title>Activeync, iislogs and user-id</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50336#M1133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have been battling a problem for quite sometime.&amp;nbsp; I think the end result is I somehow need to dig through the IISLogs for activesync information and pass it to the PA via their API.&amp;nbsp; Unfortunately I have no clue how to get started on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Story is as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typical AD environment.&amp;nbsp; Ipads and other non domain devices are coming inside our network.&amp;nbsp; Since the PA can monitor the internal exchange server logs and determine User-IDs, I figured this was the perfect solution to be able to use the PA rules by User-ID, regardless of the device.&amp;nbsp; If all else fails it falls back to the captive portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It ends up that the only time the authentication of an "activesync" client is logged to the windows event logs is during the setup process....why, I am not sure.&amp;nbsp; But I can see the activesync activity in the IIS logs but NOT in the windows event logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;End result is the Ipad IP-user mapping expires and falls back to the captive portal.&amp;nbsp; While the captive portal does work, the timeout for the user is limited to 1440 minutes and is not terribly convenient for my many types of users (young students to teachers and everything between), especially since they are already authenticating for email!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, any thoughts would be appreciated,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 30 Dec 2012 22:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50336#M1133</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2012-12-30T22:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Activeync, iislogs and user-id</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50337#M1134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;I just posted a doc that uses this specific Active Sync event as an example. Would you take a look at it and let me know if it addresses your situation?&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4423"&gt;Using Windows Events as sources for the User-ID XML-API&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 19:42:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50337#M1134</guid>
      <dc:creator>npiagentini</dc:creator>
      <dc:date>2013-01-15T19:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Activeync, iislogs and user-id</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50338#M1135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your help.&amp;nbsp; However, I am not seeing any events on my DCs, or exchange server, that contain an the IP address of one of the ipads.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please note that I am currently on Exchange 2007, not sure if that matters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 22:15:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50338#M1135</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2013-01-15T22:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Activeync, iislogs and user-id</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50339#M1136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;Can you check to see if you are getting event 4624 on your Exchange server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 22:29:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50339#M1136</guid>
      <dc:creator>npiagentini</dc:creator>
      <dc:date>2013-01-15T22:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: Activeync, iislogs and user-id</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50340#M1137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not seeing any events 4624 on Exchange.&amp;nbsp; I have enabled auditing via GPO for a number of items on the server and still nothing.&amp;nbsp; I am seeing some 4624s on the DCs, but no reference to the Ipad IP addresses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 22:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50340#M1137</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2013-01-15T22:45:49Z</dc:date>
    </item>
    <item>
      <title>Re: Activeync, iislogs and user-id</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50341#M1138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;I can see these messages on my Exchange 2007 server in my lab. Do you have all the exchange roles installed on the same server or did you separate out the CAS role? If we need to dig into the log files it becomes more complex....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 22:55:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50341#M1138</guid>
      <dc:creator>npiagentini</dc:creator>
      <dc:date>2013-01-15T22:55:46Z</dc:date>
    </item>
    <item>
      <title>Re: Activeync, iislogs and user-id</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50342#M1139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All are on a single Exchange server.&amp;nbsp; I did inherit this server and it is a sketchy build (at best).&amp;nbsp; I will look for some more places that the previous admin may have disabled some logging.&amp;nbsp; I do know they did all kinds of strange things on this network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again and any further suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 23:24:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/activeync-iislogs-and-user-id/m-p/50342#M1139</guid>
      <dc:creator>BobW</dc:creator>
      <dc:date>2013-01-15T23:24:56Z</dc:date>
    </item>
  </channel>
</rss>

