<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID mapping from Exchange logs behind F5 loadbalancer in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556770#M113009</link>
    <description>&lt;P&gt;Oh I see, I had your traffic flow all wrong, yes I would imagine that as the only device to see the x-forwarded-for header is IIS and that is where you are pulling your user-id from that you will need to user the regex to get it from IIS.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Sep 2023 15:02:45 GMT</pubDate>
    <dc:creator>laurence64</dc:creator>
    <dc:date>2023-09-06T15:02:45Z</dc:date>
    <item>
      <title>User ID mapping from Exchange logs behind F5 loadbalancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556542#M112980</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are currently trying to solve an issue with User ID mapping on Exchange cluster.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This cluster is sitting behind F5 WAF, and it is doing SNAT, therefore all request are coming from same IP. (IP of the WAF)&lt;/P&gt;
&lt;P&gt;This causes the User-IP binding to nonstop update and not reflect the reality.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On F5 we have turned on the "X-Forwarded-For" header.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have reconfigured IIS logs to show the "X-Forwarded-For" IP of the request and we can see it in the log, therefore header insertion is working.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, as far as I know, User ID agent is using Security log.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there any way how to make this work, or do we need to use Syslog and Regexp to match it from IIS logs ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 14:11:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556542#M112980</guid>
      <dc:creator>aber</dc:creator>
      <dc:date>2023-09-05T14:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: User ID mapping from Exchange logs behind F5 loadbalancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556601#M112981</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Looking at the admin guide, this may be east to do, under device &amp;gt; setup &amp;gt; content-ID there is an option for x-forwarded-for headers, in this there is a drop down for enable for user-id or for security policy and then another option to strip this as the traffic passes, this would be the first place to look I think it is fully covered in the user-id section of the admin guide, this is on version 10.1 and above, you do not mention what version you are on but as user-id is fairly static in the methods to get user-id data in I presume that some older versions also support.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 21:37:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556601#M112981</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2023-09-05T21:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: User ID mapping from Exchange logs behind F5 loadbalancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556684#M112993</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have seen this part of admin guide, and we have it "ON"for different reason. However the traffic flow is like this:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PA---------&amp;gt;F5&amp;gt;---------Exch Cluster&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Header is added at the F5 and it does not traverse PA after header is added.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently running&amp;nbsp; 11.0.2&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 07:13:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556684#M112993</guid>
      <dc:creator>aber</dc:creator>
      <dc:date>2023-09-06T07:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: User ID mapping from Exchange logs behind F5 loadbalancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556770#M113009</link>
      <description>&lt;P&gt;Oh I see, I had your traffic flow all wrong, yes I would imagine that as the only device to see the x-forwarded-for header is IIS and that is where you are pulling your user-id from that you will need to user the regex to get it from IIS.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 15:02:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-from-exchange-logs-behind-f5-loadbalancer/m-p/556770#M113009</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2023-09-06T15:02:45Z</dc:date>
    </item>
  </channel>
</rss>

