<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Credential Phishing Protection troubleshooting in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267568#M577</link>
    <description>&lt;P&gt;Hey Remko,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried walking down your version at all?&amp;nbsp; I'm not running 8.1 at the edge just yet - and I'm wondering if there are bugs in the 8.1. versions?&amp;nbsp; &amp;nbsp;I'm running 8.0.10 right now for both agents - but I'm interested to know if its versioning since I'm headed to 8.1 on the border firewalls really soon.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let me know what you think?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Laura&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jun 2019 20:38:22 GMT</pubDate>
    <dc:creator>Laura_Penhallow</dc:creator>
    <dc:date>2019-06-06T20:38:22Z</dc:date>
    <item>
      <title>Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/234453#M426</link>
      <description>&lt;P&gt;hey community -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tearing my hair out here...I've set up a RoDC in my environment and added a test group to the allowed password replication group.&amp;nbsp; I've configured the user and credential agents on the RoDC and they say connected to my firewall, and also successfully connect to the other dcs.&amp;nbsp; I can see my user to ip mapping for my test account.&amp;nbsp; On the firewall I've created a User ID agent that shows connected as well.&amp;nbsp;&lt;/P&gt;&lt;P&gt;however,&amp;nbsp;&amp;nbsp;&lt;SPAN class="s1"&gt;show user credential-filter statistics shows zero entries, I'm also seeing this in the user id logs:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;&amp;nbsp;UIA CredentialChecking error: credential enabled but no digest.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;What am I missing here?&amp;nbsp; thanks for any advice!!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 15:45:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/234453#M426</guid>
      <dc:creator>Laura_Penhallow</dc:creator>
      <dc:date>2018-10-08T15:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/252323#M504</link>
      <description>&lt;P&gt;Dear&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45823"&gt;@Laura_Penhallow&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;were you able to find a solution for your problem?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 15:16:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/252323#M504</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-03-05T15:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/252328#M505</link>
      <description>&lt;P&gt;Hi Chacko42,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I should have replied here when I solved this particular issue.&amp;nbsp; For the benefit of others (I don't think this is documented anywhere yet), the version of Credential &amp;amp; User-id agents have to be equal or less than the PAN-OS on the firewalls doing the checking.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for pinging here and reminding me! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 15:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/252328#M505</guid>
      <dc:creator>Laura_Penhallow</dc:creator>
      <dc:date>2019-03-05T15:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267249#M573</link>
      <description>&lt;P&gt;Hi, found your post and wondered if you could point me in the right direction.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to implement this as well in our environment.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have build a RODC and installed both programs&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-06-06 10_18_58-Software Updates.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20319i9B292E58DAAAAA09/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-06-06 10_18_58-Software Updates.png" alt="2019-06-06 10_18_58-Software Updates.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Running PAN-OS version 8.1.7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running into some problems though.&lt;/P&gt;&lt;P&gt;The User_ID agent runs as a service. At first via the Local System Account but if you configure it to run with a dedicated account it wants to run the service with this account&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-06-06 10_23_34-mRemoteNG - mremote.xml - ADS04 - RODC.png" style="width: 627px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20320iFB84B03784C2AB45/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-06-06 10_23_34-mRemoteNG - mremote.xml - ADS04 - RODC.png" alt="2019-06-06 10_23_34-mRemoteNG - mremote.xml - ADS04 - RODC.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Although the account is configured to run-as-a-service in the default domain policy it throws in an error when you start the service.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-06-06 10_29_05-mRemoteNG - mremote.xml - ADS04 - RODC.png" style="width: 473px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20322i6EE01A4DDCCBE114/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-06-06 10_29_05-mRemoteNG - mremote.xml - ADS04 - RODC.png" alt="2019-06-06 10_29_05-mRemoteNG - mremote.xml - ADS04 - RODC.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have used the following instructions to set this up&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/prevent-credential-phishing/configure-credential-detection-with-the-windows-based-user-id-agent.html#" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/threat-prevention/prevent-credential-phishing/configure-credential-detection-with-the-windows-based-user-id-agent.html#&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any additional instructions that I need to follow to implement this correctly on a RODC (Server 2012R2)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 08:34:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267249#M573</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2019-06-06T08:34:01Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267568#M577</link>
      <description>&lt;P&gt;Hey Remko,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you tried walking down your version at all?&amp;nbsp; I'm not running 8.1 at the edge just yet - and I'm wondering if there are bugs in the 8.1. versions?&amp;nbsp; &amp;nbsp;I'm running 8.0.10 right now for both agents - but I'm interested to know if its versioning since I'm headed to 8.1 on the border firewalls really soon.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;let me know what you think?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Laura&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jun 2019 20:38:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267568#M577</guid>
      <dc:creator>Laura_Penhallow</dc:creator>
      <dc:date>2019-06-06T20:38:22Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267721#M578</link>
      <description>&lt;P&gt;Hi Laura, thanks for your reply.&lt;/P&gt;&lt;P&gt;I have downgraded the client further to version 8.1.5-6.&lt;/P&gt;&lt;P&gt;It appears to be working correctly as long as it runs with the local system account&lt;/P&gt;&lt;P&gt;In the log I see a whole bunch of entries appearing&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-06-07 09_12_46-mRemoteNG - mremote.xml - ADS04 - RODC.png" style="width: 619px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20325iEC82C8E651ED22D4/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="2019-06-07 09_12_46-mRemoteNG - mremote.xml - ADS04 - RODC.png" alt="2019-06-07 09_12_46-mRemoteNG - mremote.xml - ADS04 - RODC.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I edit the UserIdentification setup and save it, the service starts to run with the RODC_Service account.&lt;/P&gt;&lt;P&gt;This account has the correct priviledges according to this article&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEuCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEuCAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;But but the service fails to start when started with this new account&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt; 06/04/19 11:19:03:448[Error 2382]: Start error -1!!
 06/04/19 11:19:03:448[Error  764]: Device listening thread stops timeout!
 06/04/19 11:19:45:694[ Info 2357]: ------------Service is being started------------
 06/04/19 11:19:45:694[ Info 2364]: Os version is 6.2.0.
 06/04/19 11:19:45:694[Error  675]: Cannot open config reg log key with error 5(Access is denied.&lt;/PRE&gt;&lt;P&gt;As said, as long as it runs with the system account there are green lights though in the Palo Alto User_ID Agent screen so I will try if I can get a block page when entering corporate credentials.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still a bit confused how all this works but let's give it a try &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 07:25:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267721#M578</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2019-06-07T07:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267731#M579</link>
      <description>&lt;P&gt;Hmmm,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can't seem to get this to work. Whatever I try, the Palo Alto does not detect any user credential submission. Tried various websites and categories to put the URL credential submission to block.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But unfortunately, no luck whatsoever.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think I am going to put this aside for a while and try some other time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is causing to much frustration &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remko&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 07:41:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267731#M579</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2019-06-07T07:41:54Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267732#M580</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/45031"&gt;@Indorama_Ventures&lt;/a&gt;&amp;nbsp;Can you see any blob filters if you have a look on the statistics of the User ID agent on firewall CLI?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 07:43:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267732#M580</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-06-07T07:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267733#M581</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/79934"&gt;@Chacko42&lt;/a&gt;&amp;nbsp;: Thanks for your reply. How would you check this via the commandline? I did a quick Google Search but was not able to find this. Can you advise?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 07:49:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267733#M581</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2019-06-07T07:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267735#M582</link>
      <description>&lt;P&gt;show user user-id-agent state &amp;lt;your RODC agent&amp;gt;&lt;/P&gt;&lt;P&gt;There you shood see hits at&lt;/P&gt;&lt;P&gt;num of bloomfilter requests sent :&amp;nbsp;&lt;BR /&gt;num of bloomfilter response received :&amp;nbsp;&lt;/P&gt;&lt;P&gt;In best case, the errors are low or non-existing&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 07:53:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267735#M582</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-06-07T07:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267771#M583</link>
      <description>&lt;P&gt;Thanks, I do see a couple of bloomfilter entries appear&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt; num of bloomfilter requests sent                  : 13
        num of bloomfilter response received              : 12
        num of bloomfilter response failed to proc        : 0
        num of bloomfilter resize requests sent           : 0
        Last heard(seconds ago)                           : 4&lt;/PRE&gt;&lt;P&gt;So I guess we are on the right track ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I put "domain users" in the "Allowed RODC Password Replication Group"&lt;/P&gt;&lt;P&gt;But also my personal testing account in the case there might be a problem with nested groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I tried&amp;nbsp; two different URL categories for the password credential submission&lt;/P&gt;&lt;P&gt;One for my personal NAS device (computers-and-internet-info) at home and one for NetFlix (streaming-media)&amp;nbsp;&lt;/P&gt;&lt;P&gt;But if I enter any domain credentials, they are not detected.&lt;/P&gt;&lt;P&gt;Both websites simply say the credentials are not valid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 08:51:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267771#M583</guid>
      <dc:creator>Indorama_Ventures</dc:creator>
      <dc:date>2019-06-07T08:51:11Z</dc:date>
    </item>
    <item>
      <title>Re: Credential Phishing Protection troubleshooting</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267779#M584</link>
      <description>&lt;P&gt;Okay, you're on the right track.&lt;/P&gt;&lt;P&gt;You also got a "Denied&lt;SPAN&gt;&amp;nbsp;RODC Password Replication Group" which will exclude users - so maybe that is the reason, why there are so less entries (1 bloom filter equals 1 credential) - I guess you can trigger the RODC credential sync with windows tools - you need to google that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding the "any credentials" - if you use the credential agent, the credentials are only detected, if you're web session is related to the according user.&lt;/P&gt;&lt;P&gt;If bob is mapped to ip 1.1.1.1 and bob logs in with alice credentials, nothing will happen.&lt;/P&gt;&lt;P&gt;If bob is mapped to ip 1.1.1.1 and bob logs in with his own credentials (doesn't matter which user name) - the credentials will be detected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;edit: and of course you need ssl decryption - otherwise you are unable to see the credential transmissions&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 08:57:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/credential-phishing-protection-troubleshooting/m-p/267779#M584</guid>
      <dc:creator>Chacko42</dc:creator>
      <dc:date>2019-06-07T08:57:40Z</dc:date>
    </item>
  </channel>
</rss>

