<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RDP through  GP tunnel with a different user. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483496#M104362</link>
    <description>&lt;P&gt;Hi Otakar,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We decided to apply the “split-tunnel” config to their Global-Protect setup , where only traffic sent to their HQ internal networks is put into the GP tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This appears to have resolved the overall issue. In that they can now be logged into GP with AD User-ID-bob , then RDP onto an internal server with AD User-ID-jane and GP continues to work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not exactly sure why split-tunnel has resolved it, but have tested a few times and all good&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ger&lt;/P&gt;</description>
    <pubDate>Thu, 28 Apr 2022 11:53:16 GMT</pubDate>
    <dc:creator>GerardGlynn</dc:creator>
    <dc:date>2022-04-28T11:53:16Z</dc:date>
    <item>
      <title>RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/439291#M99810</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a client that has recently run into an issue, after upgrading to PAN OS 10.1.2. When they connect to Global Protect with their username and then try to RDP through the GP tunnel to a server on site using a different user account that is not in the allowed GP user AD group, the GP tunnel looks to freeze (doesn't disconnect) and all users have to reconnect to GP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Client advised that they were able to do this prior to upgrading. The traffic log detects the different username being used through the tunnel. The client has now added the different user into the allowed GP AD group and this looks to have resolved the issue. The client can now RDP through the tunnel with this different user, when logged onto GP with their user account.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like the PAN is now smart enough to detect the different user trying to connect through the tunnel, where it may not have been before. GPS log has a gap in logging for approx. 10 mins when the different user tries to login over the tunnel, so not much there to go on by the looks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, I am wondering if this type of thing should be possible or not? Has anyone come across this type of thing before? Why does the whole tunnel seem to go down when they login as the different user?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Oct 2021 04:07:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/439291#M99810</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-10-07T04:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/440448#M99899</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;any ideas here?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Oct 2021 05:09:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/440448#M99899</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-10-13T05:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/441438#M100009</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/153031"&gt;@nikoolayy1&lt;/a&gt;&amp;nbsp;Any chance you could comment on this?&lt;/P&gt;</description>
      <pubDate>Sun, 17 Oct 2021 23:24:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/441438#M100009</guid>
      <dc:creator>Ben-Price</dc:creator>
      <dc:date>2021-10-17T23:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483195#M104333</link>
      <description>&lt;P&gt;Hi Ben,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Facing the exact same problem with GP at a customer site.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you manage to resolve the problem ?&lt;/P&gt;&lt;P&gt;I will try adding AD user-ID administrator to the AD Group GlobalProtect , but I think we are still facing that same problem where if I login to GP using AD user-ID "BobHope" , then RDP through the GP tunnel onto a server and login with AD user-ID "administrator" , it kills access through the tunnel&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help or suggestions appreciated&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;ger&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 16:13:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483195#M104333</guid>
      <dc:creator>GerardGlynn</dc:creator>
      <dc:date>2022-04-27T16:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483299#M104337</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Let me see if I understand:&lt;/P&gt;&lt;P&gt;User = john.doe logs in with global protect.&lt;/P&gt;&lt;P&gt;The PAN see's all traffic in the logs from that VPN IP address as john.doe&lt;/P&gt;&lt;P&gt;User tries to RDP to a server with jane.doe and the PAN now sees the traffic as jane.doe?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 19:56:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483299#M104337</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-04-27T19:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483483#M104360</link>
      <description>&lt;P&gt;Hi Otakar,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes thanks , that's the issue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think it's also described in this article&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleBCAS" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CleBCAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Trying to come up with a workaround for this scenario. Remote user is logged into GP with userid-1, then that user opens a remote desktop session to a server through the GP tunnel and they login with userid-2&lt;/P&gt;&lt;P&gt;This activity stops their traffic going thru GP tunnel.&lt;/P&gt;&lt;P&gt;I think its a security feature within the GP design&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 09:49:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483483#M104360</guid>
      <dc:creator>GerardGlynn</dc:creator>
      <dc:date>2022-04-28T09:49:30Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483496#M104362</link>
      <description>&lt;P&gt;Hi Otakar,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We decided to apply the “split-tunnel” config to their Global-Protect setup , where only traffic sent to their HQ internal networks is put into the GP tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This appears to have resolved the overall issue. In that they can now be logged into GP with AD User-ID-bob , then RDP onto an internal server with AD User-ID-jane and GP continues to work&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not exactly sure why split-tunnel has resolved it, but have tested a few times and all good&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ger&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 11:53:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483496#M104362</guid>
      <dc:creator>GerardGlynn</dc:creator>
      <dc:date>2022-04-28T11:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483556#M104366</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a better understanding now. We decided to use Exchange logs for user-id mapping as this seems to prevent this from happening, since the second user is not using exchange.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 28 Apr 2022 15:45:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/483556#M104366</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2022-04-28T15:45:10Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484002#M104402</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/29557"&gt;@GerardGlynn&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;What you experiencing only make sense if you have User-ID agent deployed in your network (either via separate agent installed on server or the integrated agent in the FW itself).&lt;/P&gt;&lt;P&gt;If that is the case it make sense to experience exactly what is described in the link you provide.&lt;/P&gt;&lt;P&gt;- When user login to GP, firewall will use that information to create ip-to-user mapping (since it already have the required information: authenticated user and allocated IP address)&lt;/P&gt;&lt;P&gt;- When user makes RDP login attempt, this will create security log under the Domain Controller. Which will be picked up by the User-ID agent and override the existing user-to-ip mapping with the username used for the RDP connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apart from &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt; suggested approach I would add another two:&lt;/P&gt;&lt;P&gt;- As suggested in the article you can add the username used for the RDP to ignore list on the user-id agent. This will tell the agent to ignore any logon events and not create user-to-ip mapping for that user&lt;/P&gt;&lt;P&gt;- What I would suggest in your case is to add the GP network to user-id agent exclude network list. This will tell the agent to ignore all events for users connecting from that network. I believe this make sense, because you already have user-ip-mapping from GP, which is far more accurate from the agent, so it doesn't make sense to receive mapping from somewhere else, for something that FW already knows.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Apr 2022 21:28:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484002#M104402</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-04-30T21:28:07Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484468#M104431</link>
      <description>&lt;P&gt;Hi Astardzhiev,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your post which is very helpful. Of course, the split-tunnel idea did not fully resolve the issue so have abandoned that for now&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will try your suggestion with excluding the GP-remote-LAN from the user-ID detection, which seems like a good solution&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 09:34:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484468#M104431</guid>
      <dc:creator>GerardGlynn</dc:creator>
      <dc:date>2022-05-03T09:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484473#M104433</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Astardzhiev,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you apply your workaround below, do you also have to remove source user-id matching from the security policies relating to inbound Global-Protect traffic ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- What I would suggest in your case is to add the GP network to user-id agent exclude network list. This will tell the agent to ignore all events for users connecting from that network. I believe this make sense, because you already have user-ip-mapping from GP, which is far more accurate from the agent, so it doesn't make sense to receive mapping from somewhere else, for something that FW already knows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ger&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 10:20:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484473#M104433</guid>
      <dc:creator>GerardGlynn</dc:creator>
      <dc:date>2022-05-03T10:20:47Z</dc:date>
    </item>
    <item>
      <title>Re: RDP through  GP tunnel with a different user.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484477#M104434</link>
      <description>&lt;P&gt;Ignore that last message about the security policies, I had forgotten to add an "include-list" of 0.0.0.0/0 to&amp;nbsp; accompany the "exclude-list"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;seems to be working now&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks again&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 10:58:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rdp-through-gp-tunnel-with-a-different-user/m-p/484477#M104434</guid>
      <dc:creator>GerardGlynn</dc:creator>
      <dc:date>2022-05-03T10:58:52Z</dc:date>
    </item>
  </channel>
</rss>

