<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PA User identification in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15890#M11598</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How PA decide on user IDs, for example if i have an IP that the user was mapped from UIA, and then a security log in AD map this IP to another user?&lt;/P&gt;&lt;P&gt;or a user that loging with global protect through local DB, and then authenticate to AD, and the PA gets a new mapping from the agent ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 28 Jan 2014 07:22:59 GMT</pubDate>
    <dc:creator>minow</dc:creator>
    <dc:date>2014-01-28T07:22:59Z</dc:date>
    <item>
      <title>PA User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15890#M11598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How PA decide on user IDs, for example if i have an IP that the user was mapped from UIA, and then a security log in AD map this IP to another user?&lt;/P&gt;&lt;P&gt;or a user that loging with global protect through local DB, and then authenticate to AD, and the PA gets a new mapping from the agent ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 07:22:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15890#M11598</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-01-28T07:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: PA User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15891#M11599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Pls&lt;/SPAN&gt; go through this document&amp;nbsp; to understand the User-Identification&amp;nbsp; working functionality : &lt;A href="https://live.paloaltonetworks.com/docs/DOC-1807"&gt;User Identification Tech Note - PAN-OS 4.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 Jan 2014 15:55:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15891#M11599</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-28T15:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: PA User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15892#M11600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes i know how it works but i have a GP user and sometimes the user is changed and sometimes does not &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i mean changed from GP to AD, only somtime after a user loging to RDP server, or does the UID service just update the IP-user-mapping regardless the current mapping source?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP address:&amp;nbsp; x.x.x.x (vsys1)&lt;/P&gt;&lt;P&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain\user&lt;/P&gt;&lt;P&gt;From:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AD&lt;/P&gt;&lt;P&gt;Idle Timeout: 2692s&lt;/P&gt;&lt;P&gt;Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 2689s&lt;/P&gt;&lt;P&gt;Groups that the user belongs to (used in policy)&lt;/P&gt;&lt;P&gt;Group(s):&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@PA(active)&amp;gt; show user ip-user-mapping ip x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IP address:&amp;nbsp; x.x.x.x (vsys1)&lt;/P&gt;&lt;P&gt;User:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; domain\user&lt;/P&gt;&lt;P&gt;From:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; GP&lt;/P&gt;&lt;P&gt;Idle Timeout: 17889s&lt;/P&gt;&lt;P&gt;Max. TTL:&amp;nbsp;&amp;nbsp;&amp;nbsp; 17889s&lt;/P&gt;&lt;P&gt;Groups that the user belongs to (used in policy)&lt;/P&gt;&lt;P&gt;Group(s):&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 17:49:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15892#M11600</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-01-29T17:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: PA User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15893#M11601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So an ip gets identified as being mapped from GP and the very same ip changes the source to AD, is that the issue, please let us know.The ip pool given to your GP users are different from your internal users right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 19:56:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15893#M11601</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2014-01-29T19:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: PA User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15894#M11602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, adn the zone of the GP user is defferent&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have read that the the mapping of the user to ip of a GP user is bind to the connection of the client to the GW, so as soon as the user log in/out the mapping created and removed,&lt;/P&gt;&lt;P&gt;can i remote the UID from the zone or exclude the mapping on the GP pool have someone tried that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Jan 2014 10:47:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-user-identification/m-p/15894#M11602</guid>
      <dc:creator>minow</dc:creator>
      <dc:date>2014-01-31T10:47:11Z</dc:date>
    </item>
  </channel>
</rss>

