<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User to IP mapping for LAN with computer on hybernet/sleep in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/488733#M104852</link>
    <description>&lt;P&gt;1. Is WMI probing still recommended option or no longer in use..?&amp;nbsp; Not recommend..as it is too chatty.&lt;/P&gt;
&lt;P&gt;2. for the scenario described... How to handle this use case..?&amp;nbsp;&amp;nbsp;&amp;nbsp; Increase the timeout for the userID from 45 minutes to 24 hours.&lt;/P&gt;
&lt;P&gt;Now personally, even if the machine is asleep during the night, GroupPolicy states that there should be GPO "check ins" at 90 min intervals throughout the day (please research/confirm how often GPO checkins are preferred on MS)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Scenario&amp;nbsp; How to handle this use case..?&amp;nbsp;&amp;nbsp; GPO checkins should still be occuring every 90 minutes (please confirm).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please consider implementing Authentication Policy to help force users to re-authenticate to the network if their IP is "unknown" to the network.&amp;nbsp; (&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/authentication/authentication-policy" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/authentication/authentication-policy&lt;/A&gt;)&lt;/P&gt;</description>
    <pubDate>Fri, 20 May 2022 02:30:20 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2022-05-20T02:30:20Z</dc:date>
    <item>
      <title>User to IP mapping for LAN with computer on hybernet/sleep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/488120#M104779</link>
      <description>&lt;P&gt;I have Palo Alto firewall and implemented the user ID in our environment. I am looking for some help on specific use case. I am hoping to get some answers/guidance for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewalls : PA-820/850 as well VM-300&lt;/P&gt;&lt;P&gt;PAN OS : 9.1.13-h3/9.1.9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have install the windows based user ID agent on couple of servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Windows Server OS : Server 2019 Standard&lt;/P&gt;&lt;P&gt;Palo's Windows User ID Agent : Version 9.1.2-9&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Queries:&lt;/P&gt;&lt;P&gt;1. Is WMI probing still recommended&amp;nbsp;option or no longer in use..?&lt;/P&gt;&lt;P&gt;2. We have lot of users don't shutdown their computers. I see a issue in mapping ip to user for these users/computers. They hybernet/sleep their computers and come to office next day, connect to wired network but windows users ID agent is not able to map their ip to user because there is no logon event on Domain controller. How to handle this use case..?&lt;/P&gt;&lt;P&gt;3. The second use case is that user is connected to wireless network and already logged in to computer on wireless network when in meeting. User comes back to desk and connect to docking station or wired network. I believe again there will not be any login event with wired IP address so it is not able to map the wired IP to user. How to handle this use case..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using the 802.1x on wireless but there is no Authentication on Wired network currently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other option to make sure all these use cases are covered..?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2022 08:09:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/488120#M104779</guid>
      <dc:creator>Niren.Vekaria</dc:creator>
      <dc:date>2022-05-18T08:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: User to IP mapping for LAN with computer on hybernet/sleep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/488733#M104852</link>
      <description>&lt;P&gt;1. Is WMI probing still recommended option or no longer in use..?&amp;nbsp; Not recommend..as it is too chatty.&lt;/P&gt;
&lt;P&gt;2. for the scenario described... How to handle this use case..?&amp;nbsp;&amp;nbsp;&amp;nbsp; Increase the timeout for the userID from 45 minutes to 24 hours.&lt;/P&gt;
&lt;P&gt;Now personally, even if the machine is asleep during the night, GroupPolicy states that there should be GPO "check ins" at 90 min intervals throughout the day (please research/confirm how often GPO checkins are preferred on MS)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Scenario&amp;nbsp; How to handle this use case..?&amp;nbsp;&amp;nbsp; GPO checkins should still be occuring every 90 minutes (please confirm).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please consider implementing Authentication Policy to help force users to re-authenticate to the network if their IP is "unknown" to the network.&amp;nbsp; (&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/authentication/authentication-policy" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/authentication/authentication-policy&lt;/A&gt;)&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 02:30:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/488733#M104852</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2022-05-20T02:30:20Z</dc:date>
    </item>
    <item>
      <title>Re: User to IP mapping for LAN with computer on hybernet/sleep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/489170#M104868</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/172566"&gt;@Niren.Vekaria&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In addition to what&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;mentioned, if you have Exchange in your environment you can use that to pull user-id from its logs as well. Exchange in general causes way more events to read from during normal operations than a just pulling through AD DCs.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 21 May 2022 02:53:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/489170#M104868</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2022-05-21T02:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: User to IP mapping for LAN with computer on hybernet/sleep</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/497696#M105129</link>
      <description>&lt;P&gt;Thanks &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/113304"&gt;@S.Cantwell&lt;/a&gt;&amp;nbsp;for your response.&lt;/P&gt;&lt;P&gt;We are using Microsoft Office 365 and I think we can't look at events of M365 like on-prem exchange server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already increased timeout and it is helping but still I see some users not re-starting their computers and connect via LAN, IP and user mapping is not happening. GPO is getting pushed every 30 mins but I thought it will not create the login event for user ID agent to map the user to IP..?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will have to explore the option of Authentication policy to see how that can help.. It will be challenging to implement it as we have few machines which are not part of domain as well.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jun 2022 01:24:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-to-ip-mapping-for-lan-with-computer-on-hybernet-sleep/m-p/497696#M105129</guid>
      <dc:creator>Niren.Vekaria</dc:creator>
      <dc:date>2022-06-02T01:24:49Z</dc:date>
    </item>
  </channel>
</rss>

