<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-id agent timeout integration with dhcp lease timeout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483174#M104331</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;let's suppose these conditions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- interface with dhcp enabled, 24 hours lease timeout, ip range (for example) 192.168.3.0/24&lt;/P&gt;&lt;P&gt;- user-id agent enabled with 45 minutes timeout&lt;/P&gt;&lt;P&gt;- virtual machine environment with non persistent vm, so when a machine is powered off it will be destroyed and recreated with a new mac address&lt;/P&gt;&lt;P&gt;- a machine cannot do web-browsing without user-id&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;26/04/2022 11:03:49 -&amp;gt; machine MACHINE1 got ip from dhcp, 192.168.3.1&lt;/P&gt;&lt;P&gt;27/04/2022 11:00:00 -&amp;gt; user USER1 log into MACHINE1, so a user-id mapping will be created between 192.168.3.1 and USER1&lt;/P&gt;&lt;P&gt;27/04/2022 11:02:00 -&amp;gt; user USER1 log off from MACHINE1&lt;/P&gt;&lt;P&gt;27/04/2022 11:02:30 -&amp;gt; machine MACHINE1 will be recreated with a new mac address and got 192.68.3.100 from dhcp&lt;/P&gt;&lt;P&gt;27/04/2022 11:03:00 -&amp;gt; machine MACHINE1 release dhcp address got 24 hours ago&lt;/P&gt;&lt;P&gt;27/04/2022 11:20:00 -&amp;gt; a user with a pc connect his machine to the network and he got 192.168.3.1&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Between 11:20:00 and 11:45:00 the user "unknown" with his pc can do web-browsing with ip 192.168.3.1 because he's recognized as USER1&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;27/04/2022 11:45:00 -&amp;gt; the user-id mapping between USER1 and 192.168.3.1 will be deleted, the "unknown" user can't web-browsing anymore&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This could cause&lt;/P&gt;&lt;P&gt;- unknown user do web-browsing without having rights&lt;/P&gt;&lt;P&gt;- unknown user could visit sites as USER1, so the logs are not consistent&lt;/P&gt;&lt;P&gt;- unknown user can have access to other network segment due to the fact that he is presenting as USER1&lt;/P&gt;&lt;P&gt;- and so on..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any hint on this, other that reducing dhcp timeout that could mitigate a bit the problem, but it doesn't resolve it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously the ideal could be that the dhcp does not assign an ip if there is already a user-id agent associated to the same ip with a different mac address, but I think I'm asking too much..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Wed, 27 Apr 2022 15:39:27 GMT</pubDate>
    <dc:creator>N2Z2</dc:creator>
    <dc:date>2022-04-27T15:39:27Z</dc:date>
    <item>
      <title>User-id agent timeout integration with dhcp lease timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483174#M104331</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;let's suppose these conditions:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- interface with dhcp enabled, 24 hours lease timeout, ip range (for example) 192.168.3.0/24&lt;/P&gt;&lt;P&gt;- user-id agent enabled with 45 minutes timeout&lt;/P&gt;&lt;P&gt;- virtual machine environment with non persistent vm, so when a machine is powered off it will be destroyed and recreated with a new mac address&lt;/P&gt;&lt;P&gt;- a machine cannot do web-browsing without user-id&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;An example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;26/04/2022 11:03:49 -&amp;gt; machine MACHINE1 got ip from dhcp, 192.168.3.1&lt;/P&gt;&lt;P&gt;27/04/2022 11:00:00 -&amp;gt; user USER1 log into MACHINE1, so a user-id mapping will be created between 192.168.3.1 and USER1&lt;/P&gt;&lt;P&gt;27/04/2022 11:02:00 -&amp;gt; user USER1 log off from MACHINE1&lt;/P&gt;&lt;P&gt;27/04/2022 11:02:30 -&amp;gt; machine MACHINE1 will be recreated with a new mac address and got 192.68.3.100 from dhcp&lt;/P&gt;&lt;P&gt;27/04/2022 11:03:00 -&amp;gt; machine MACHINE1 release dhcp address got 24 hours ago&lt;/P&gt;&lt;P&gt;27/04/2022 11:20:00 -&amp;gt; a user with a pc connect his machine to the network and he got 192.168.3.1&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;Between 11:20:00 and 11:45:00 the user "unknown" with his pc can do web-browsing with ip 192.168.3.1 because he's recognized as USER1&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;27/04/2022 11:45:00 -&amp;gt; the user-id mapping between USER1 and 192.168.3.1 will be deleted, the "unknown" user can't web-browsing anymore&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This could cause&lt;/P&gt;&lt;P&gt;- unknown user do web-browsing without having rights&lt;/P&gt;&lt;P&gt;- unknown user could visit sites as USER1, so the logs are not consistent&lt;/P&gt;&lt;P&gt;- unknown user can have access to other network segment due to the fact that he is presenting as USER1&lt;/P&gt;&lt;P&gt;- and so on..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any hint on this, other that reducing dhcp timeout that could mitigate a bit the problem, but it doesn't resolve it?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously the ideal could be that the dhcp does not assign an ip if there is already a user-id agent associated to the same ip with a different mac address, but I think I'm asking too much..&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 15:39:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483174#M104331</guid>
      <dc:creator>N2Z2</dc:creator>
      <dc:date>2022-04-27T15:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: User-id agent timeout integration with dhcp lease timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483307#M104339</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you have an AD or other radius system, I would use those logs instead of DHCP for user-id.. I had other issues in the past with user -id not being quick enough with AD so I started using Exchange logs, however there are issues with this as well, i.e. need to have outlook open, etc. You could install global protect on these VM's as the base image and have it update the PAN, e.g. internal gateway?&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH1CAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClH1CAK&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Just some thoughts.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 20:08:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483307#M104339</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-04-27T20:08:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-id agent timeout integration with dhcp lease timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483414#M104345</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/205869"&gt;@N2Z2&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Anytime you have a situation like this, I&amp;nbsp;&lt;EM&gt;really&amp;nbsp;&lt;/EM&gt;recommend using GlobalProtect and user certificates to handle the User-ID portion of things if you have an internal PKI infrastructure setup. It's the best experience that essentially eliminates the capability for a user to get an IP address with stale User-ID information associated with it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that isn't an option for you, then I would recommend following&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;'s advice and using AD/Radius for user-id information so that the user logging into the VM will update the ip-user-mapping and overwrite the stale User-ID information.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran into one instance a while back that the environment was doing essentially what you are doing now. The solution in that case was a lot of scripting and log scrubbing and using the API to update user information manually. It wasn't an elegant solution, but it got them through until a proper GlobalProtect installation could be configured and deployed in their environment.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 00:44:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483414#M104345</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-04-28T00:44:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-id agent timeout integration with dhcp lease timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483471#M104357</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've an AD domain connected for user-id agent, but in the example in the first post, the user "unknown" connects his MacBook to the network and he doesn't do login to AD domain (for example, it could do web-browsing with an ip based policy and a static dhcp lease for his mac address, I can't see the user but I'm 100% sure that the ip is his ip address, without considering mac spoofing).&lt;/P&gt;&lt;P&gt;The perfect solution will be "connect your MacBook to another vlan to get the address from another subnet" and usually this is the way, but there are a couple of case in which I cannot do that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe I could put a logoff script via gpo (yet another not elegant solution, as you said) that could use an API to invalidate the mapping?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe something like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;curl -F key=&amp;lt;mykey&amp;gt; --form file=@&amp;lt;myfile&amp;gt; "&lt;A href="https://myfirewallip/api/?type=user-id" target="_blank" rel="noopener"&gt;https://myfirewallip/api/?type=user-id&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;using this as &amp;lt;myfile&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;lt;uid-message&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;payload&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;logout&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;entry user="domain\user1" ip="&amp;lt;local_ip_go_from_script&amp;gt;"&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;/logout&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;/payload&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;type&amp;gt;update&amp;lt;/type&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;version&amp;gt;1.0&amp;lt;/version&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;&amp;lt;/uid-message&amp;gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;N.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 08:58:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483471#M104357</guid>
      <dc:creator>N2Z2</dc:creator>
      <dc:date>2022-04-28T08:58:04Z</dc:date>
    </item>
    <item>
      <title>Re: User-id agent timeout integration with dhcp lease timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483554#M104365</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;So if you have a user, ie a guest, on your network, you can use the captive portal to capture their user name.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/user-id/user-id-concepts/user-mapping/captive-portal" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/7-1/pan-os-admin/user-id/user-id-concepts/user-mapping/captive-portal&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Just a thought.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 15:41:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483554#M104365</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-04-28T15:41:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-id agent timeout integration with dhcp lease timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483777#M104381</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;yes, it could be a solution.&lt;/P&gt;&lt;P&gt;Thanks for the hint&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 08:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-timeout-integration-with-dhcp-lease-timeout/m-p/483777#M104381</guid>
      <dc:creator>N2Z2</dc:creator>
      <dc:date>2022-04-29T08:07:19Z</dc:date>
    </item>
  </channel>
</rss>

