<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How can I see which user access what website in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-which-user-access-what-website/m-p/508063#M105799</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently managing a PA-220 and have setup URL-filtering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see which IP-addresses that tries to access the blocked websites.&lt;/P&gt;&lt;P&gt;Is there any possibility to resolve/match this IP-address to our DHCP server to see exactly which mac/computer it is accessing the blocked sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have it setup so all computers on our company network have unique names.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently what I have to do is to check the url filtering log and look for the IP and then crossmatch that IP with dhcp server.&lt;/P&gt;&lt;P&gt;Or is there any other way to do this thats less time consuming.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there are some ways to connect the Palo alto to Active directory but im not sure exactly how to solve this.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2022 12:40:42 GMT</pubDate>
    <dc:creator>Rasmus_Edholm</dc:creator>
    <dc:date>2022-07-06T12:40:42Z</dc:date>
    <item>
      <title>How can I see which user access what website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-which-user-access-what-website/m-p/508063#M105799</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm currently managing a PA-220 and have setup URL-filtering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see which IP-addresses that tries to access the blocked websites.&lt;/P&gt;&lt;P&gt;Is there any possibility to resolve/match this IP-address to our DHCP server to see exactly which mac/computer it is accessing the blocked sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have it setup so all computers on our company network have unique names.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently what I have to do is to check the url filtering log and look for the IP and then crossmatch that IP with dhcp server.&lt;/P&gt;&lt;P&gt;Or is there any other way to do this thats less time consuming.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there are some ways to connect the Palo alto to Active directory but im not sure exactly how to solve this.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 12:40:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-which-user-access-what-website/m-p/508063#M105799</guid>
      <dc:creator>Rasmus_Edholm</dc:creator>
      <dc:date>2022-07-06T12:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see which user access what website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-which-user-access-what-website/m-p/508077#M105800</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/154062"&gt;@Rasmus_Edholm&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;It sound you need User-ID. I would suggest you to take a look at the following links as starting point&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/user-id-overview" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/user-id/user-id-overview&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClRyCAK&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Cm5bCAC&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I try to sum it up - As firewall works with IP addresses, you need a way to associate the soure IP (from where the traffic originates) with username. Palo Alto is capable to use different sources for such information. Once the firewall receive user-to-ip mapping you will see the associated username in the logs. You can even create the firewall rules allowing user/user groups.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My personal recommendation is to use GlobalProtect with Internal Gateway as source of user-to-ip mapping.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 13:23:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-which-user-access-what-website/m-p/508077#M105800</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-07-06T13:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can I see which user access what website</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-which-user-access-what-website/m-p/508087#M105805</link>
      <description>&lt;P&gt;Hi, thanks for your answer. I will definitely take a look at those links you posted.&lt;/P&gt;&lt;P&gt;But for user-id do I need to have the computers join the AD, or is it enough to just create the computers manually in AD(via powershell).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 14:16:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-see-which-user-access-what-website/m-p/508087#M105805</guid>
      <dc:creator>Rasmus_Edholm</dc:creator>
      <dc:date>2022-07-06T14:16:36Z</dc:date>
    </item>
  </channel>
</rss>

