<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: USER-ID Settings: Why is the &amp;quot;User Identification Timeout&amp;quot; a global setting in Automation/API Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/user-id-settings-why-is-the-quot-user-identification-timeout/m-p/21666#M554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like you are using the onbox agent to send the syslog to.&amp;nbsp; If you have the resource why don't you install the V6 UserID agent on a server and point the syslog from the Juniper to that.&amp;nbsp; The timeout setting on the agent will then be unique to only your syslog users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do however agree that you should be able to set different timeout values for each type of user-ip mapping.&amp;nbsp; But the above should be a sufficient work around&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Apr 2014 08:34:06 GMT</pubDate>
    <dc:creator>CHammock</dc:creator>
    <dc:date>2014-04-22T08:34:06Z</dc:date>
    <item>
      <title>USER-ID Settings: Why is the "User Identification Timeout" a global setting</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/user-id-settings-why-is-the-quot-user-identification-timeout/m-p/21664#M552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i use a syslog collector to receive ip-user-mappings from an Juniper Secure Access Gateway.&lt;/P&gt;&lt;P&gt;It works quite fine, i created a custom syslog filter on my paloalto and created the correspondig Server Monitor entry for my Juniper Systems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;a simple "show user server-monitor state all" on the commandline shows that the collector receives the corresponding logs and that the filter works:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; UDP Syslog Listener Service is enabled&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSL Syslog Listener Service is disabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Proxy: xxxxx&amp;nbsp;&amp;nbsp;&amp;nbsp; Host: xxxxx(1xxx.xxx.xxx.xxx)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; number of log messages&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 83&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; number of auth. success messages&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 16&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;additionaly the commands "show user ip-user-mapping all type SYSLOG" show that the current mappings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; From&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;IdleTimeout(s) MaxTimeout(s)&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;---------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; --------------------------- --------------&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------------&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;xxx.xxx.xxx.xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYSLOG&amp;nbsp; xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;2429&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2429&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;xxx.xxx.xxx.xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYSLOG&amp;nbsp; xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;1619&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1619&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;xxx.xxx.xxx.xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYSLOG&amp;nbsp; xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;2404&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2404&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;xxx.xxx.xxx.xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SYSLOG&amp;nbsp; xxx&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;2678&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2678&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Total: 4 users&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The probem is that my juniper does not log any keep alive messages, so when the "Idle Timeout" or the "Max Timeout" on the paloalto for the mapping is reached. The mapping will be deleted, regardless of a still existing session on my juniper.&lt;/P&gt;&lt;P&gt;I thought that one solution might be to increase the "User Identification Timeout" but then i saw that this is a global setting on the pa and that this setting will also increase the Timeouts for my AD User-Agent and my Terminalserver-Agents.&lt;/P&gt;&lt;P&gt;Why can there be different timeout values for the different User-ID Domains, i saw that you already seperated them ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; AD&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Active Directory&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; CP&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Captive Portal&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; EDIR &lt;/TD&gt;&lt;TD&gt;eDirectory&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; GP&amp;nbsp;&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;Global Protect&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; NTLM &lt;/TD&gt;&lt;TD&gt;NTLM&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp; SSL/VPN&amp;nbsp;&amp;nbsp; SSL VPN&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; SYSLOG&lt;/TD&gt;&lt;TD&gt;Syslog&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; UIA&amp;nbsp; &lt;/TD&gt;&lt;TD&gt;User-ID Agent&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp; UNKNOWN&amp;nbsp;&amp;nbsp; Unknown&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp; XMLAPI&lt;/TD&gt;&lt;TD&gt;XML API&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Christoph&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Mar 2014 13:05:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/user-id-settings-why-is-the-quot-user-identification-timeout/m-p/21664#M552</guid>
      <dc:creator>ottench</dc:creator>
      <dc:date>2014-03-19T13:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: USER-ID Settings: Why is the "User Identification Timeout" a global setting</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/user-id-settings-why-is-the-quot-user-identification-timeout/m-p/21665#M553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You could parse syslog messages on another device (ex. Linux), and next generate XML-API update request to USER-ID with choosen timeout value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Juniper -&amp;gt; (Syslog) -&amp;gt; Linux Server -&amp;gt; (XML-API) -&amp;gt; Palo Device&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4968"&gt;Setting the Timeout for User to IP mapping Created Using User-ID XML-API&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.rsyslog.com/doc/v8-stable/configuration/actions.html?highlight=execute#shell-execute" title="http://www.rsyslog.com/doc/v8-stable/configuration/actions.html?highlight=execute#shell-execute"&gt;http://www.rsyslog.com/doc/v8-stable/configuration/actions.html?highlight=execute#shell-execute&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;T.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Apr 2014 20:44:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/user-id-settings-why-is-the-quot-user-identification-timeout/m-p/21665#M553</guid>
      <dc:creator>tomasz.niewdana</dc:creator>
      <dc:date>2014-04-19T20:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: USER-ID Settings: Why is the "User Identification Timeout" a global setting</title>
      <link>https://live.paloaltonetworks.com/t5/automation-api-discussions/user-id-settings-why-is-the-quot-user-identification-timeout/m-p/21666#M554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks like you are using the onbox agent to send the syslog to.&amp;nbsp; If you have the resource why don't you install the V6 UserID agent on a server and point the syslog from the Juniper to that.&amp;nbsp; The timeout setting on the agent will then be unique to only your syslog users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do however agree that you should be able to set different timeout values for each type of user-ip mapping.&amp;nbsp; But the above should be a sufficient work around&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 08:34:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/automation-api-discussions/user-id-settings-why-is-the-quot-user-identification-timeout/m-p/21666#M554</guid>
      <dc:creator>CHammock</dc:creator>
      <dc:date>2014-04-22T08:34:06Z</dc:date>
    </item>
  </channel>
</rss>

