<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Users failed to authenticate when they have Windows7 in their PCs...? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14737#M10818</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not asking about problems with the PANAgent installed on windows7. The question is if there is any knwon issue about PCs of users with Windows7. We're detecting some problems with the same Policies configured in our PA, when the user changes its PC from Windows XP to Windows 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the user had WindowsXP, things run properly and the PANAgent was able to identify user-IP. Now, when the user has Windows7, the PANAgent isn't able to identify the same user-IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for description of debugs,&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Mar 2010 14:10:21 GMT</pubDate>
    <dc:creator>fw_admin</dc:creator>
    <dc:date>2010-03-16T14:10:21Z</dc:date>
    <item>
      <title>Users failed to authenticate when they have Windows7 in their PCs...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14735#M10816</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've got two PANAgents in W2008 and we've seen that our users running Windows 7 have some problems to be authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our partner has adviced us that NetBios probing doesn't work with Windows7, that in new version of PAN OS 3.1 will be supported via WMI. But is there any known issue related to windows7 in the query to DCs from the PANAgent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to see from which DC is the PANAgent obtaining its information for mapping IP-user? What does it show each level of debug logging?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Feb 2010 14:30:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14735#M10816</guid>
      <dc:creator>fw_admin</dc:creator>
      <dc:date>2010-02-18T14:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Users failed to authenticate when they have Windows7 in their PCs...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14736#M10817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So far we don't know of any issues running the PAN Agent on Windows 7. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The statements in the PAN Agent logs beginning with "SERVICE_TICKET_GRANTED" will indicate the IP of the DC server and the name/IP of the user. &lt;/P&gt;&lt;P&gt;The debug options for the PAN Agent logging are:&lt;/P&gt;&lt;P&gt;None - No debugging output&lt;/P&gt;&lt;P&gt;Info - Default value.&amp;nbsp;&amp;nbsp; Includes all error/warning log output, as well as some system running information logs.&lt;/P&gt;&lt;P&gt;Debug- Includes all Info level log output, as well as most Debug related logs.&lt;/P&gt;&lt;P&gt;Verbose - Includes all Info and Debug level log output, as well as all verbose logs.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Feb 2010 00:19:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14736#M10817</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-02-19T00:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Users failed to authenticate when they have Windows7 in their PCs...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14737#M10818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not asking about problems with the PANAgent installed on windows7. The question is if there is any knwon issue about PCs of users with Windows7. We're detecting some problems with the same Policies configured in our PA, when the user changes its PC from Windows XP to Windows 7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the user had WindowsXP, things run properly and the PANAgent was able to identify user-IP. Now, when the user has Windows7, the PANAgent isn't able to identify the same user-IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for description of debugs,&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Mar 2010 14:10:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14737#M10818</guid>
      <dc:creator>fw_admin</dc:creator>
      <dc:date>2010-03-16T14:10:21Z</dc:date>
    </item>
    <item>
      <title>Re: Users failed to authenticate when they have Windows7 in their PCs...?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14738#M10819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Fw-admin,&lt;/P&gt;&lt;P&gt;there should be no issues with users running windows7. How the user identification agent maps users to ips has more to do with active directory. The user identification agent actually reads the security logs from the domain controller/s.&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The domain controller must log "successful login" information.&lt;/P&gt;&lt;P&gt;These are the event ids that pan-agent looks at:&lt;/P&gt;&lt;P&gt;2000 $ 2003&lt;/P&gt;&lt;P&gt;SUCCESS_NET_LOGON = 540,&lt;/P&gt;&lt;P&gt;AUTH_TICKET_GRANTED = 672,&lt;/P&gt;&lt;P&gt;SERVICE_TICKET_GRANTED = 673,&lt;/P&gt;&lt;P&gt;TICKET_GRANTED_RENEW = 674,&lt;/P&gt;&lt;P&gt;ACCOUNT_USED_FOR_LOGON = 680,&lt;/P&gt;&lt;P&gt;2008&lt;/P&gt;&lt;P&gt;LOGON_SUCCESS_W2008 = 4624,&lt;/P&gt;&lt;P&gt;AUTH_TICKET_GRANTED_W2008 = 4768,&lt;/P&gt;&lt;P&gt;TICKET_GRANTED_RENEW_W2008 = 4770,&lt;/P&gt;&lt;P&gt;ACCOUNT_USED_FOR_LOGON_W2008 = 4776,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Howver, if we you have the user identification agent configured to also use Netbios probe, then the user identification agent will also send out a probe to all of the machines in the subnet for the allow list that you configured on the user identification agent. Then the user to ip mapping can change based on the results from the netbios probe. If a machine does not respond to the netbios probe or if there was a networking issue that caused the netbios probe to not reach a machine, then that user will be identified as unknown. Desktop hosts may be unable to respond to probes, due to 3rd party security applications or use of Windows Vista....thus, it is possible that Windows7 may be blocking or netbios probes or simply not responding to them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Mar 2010 16:35:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/users-failed-to-authenticate-when-they-have-windows7-in-their/m-p/14738#M10819</guid>
      <dc:creator>swhyte</dc:creator>
      <dc:date>2010-03-18T16:35:51Z</dc:date>
    </item>
  </channel>
</rss>

