<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless USER-ID timeout in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587708#M117242</link>
    <description>&lt;P&gt;What &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; is suggesting is a good approach.&amp;nbsp; You can configure a session timeout on the SSID or a re-authentication timeout on the RADIUS server, e.g. Cisco ISE.&amp;nbsp; This will force the client to re-authenticate.&amp;nbsp; These timers and your User-ID cache timeout should be similar.&lt;/P&gt;</description>
    <pubDate>Wed, 22 May 2024 22:28:32 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2024-05-22T22:28:32Z</dc:date>
    <item>
      <title>Agentless USER-ID timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587547#M117219</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have USER-ID setup to get our wifi logs and that is working well for most of our devices however we have an issue where the iPads will initally get a connection but then after timeout period set in User Identification Timeout they remain connected without a username and therefore will have no access. The ipads never drop wifi even when asleep for days at a time so it doesnt trigger another log and I havent been able to get the ipad to drop the wifi connection while asleep.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see there is an option in User-ID to turn off User identification timeout however I feel like that might cause more issues.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help will be appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 05:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587547#M117219</guid>
      <dc:creator>MichaelSeddon</dc:creator>
      <dc:date>2024-05-22T05:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587555#M117221</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We have USER ID set up to get our WiFi logs, and it works well for&amp;nbsp;&lt;A href="https://www-indigocard.com" target="_self"&gt;My Indigo Card&lt;/A&gt; most devices. However iPads connect initially but lose access after the User Identification Timeout period because they stay connected without re-authenticating. The iPads don't drop WiFi even when asleep, so they don't trigger a new log.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 04:08:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587555#M117221</guid>
      <dc:creator>donald795</dc:creator>
      <dc:date>2024-05-23T04:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587629#M117225</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/92308397"&gt;@MichaelSeddon&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;...but then after timeout period set in User Identification Timeout they remain connected without a username and therefore will have no access...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;After the user-id timeout, they stay connected?&amp;nbsp; Connected to what?&amp;nbsp; The WiFi network or the known user for the device stays in the firewall?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the user-id timeout the ip to user-id mapping should be removed from the firewall.&amp;nbsp; Depending on the hardware platform there's a MP and DP.&amp;nbsp; So check there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if you're reporting that the user-id timeout is being reached, but expecting the iPad to be disconnected from the WiFi network, that will not happen.&amp;nbsp; The firewall user-id timeout will have no bearing on being removed from the WiFi network.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 13:05:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587629#M117225</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-05-22T13:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587706#M117241</link>
      <description>&lt;P&gt;You could probably resolve this by getting the WiFi to deauth the existing session so that the iPad has to go through an entire authentication again and map properly. Might also look to see if your wireless has the ability to setup a session-timeout to force it to reauthenticate again. Cisco as an example you could set this up on the wireless profile policy.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 21:47:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587706#M117241</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-05-22T21:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587708#M117242</link>
      <description>&lt;P&gt;What &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt; is suggesting is a good approach.&amp;nbsp; You can configure a session timeout on the SSID or a re-authentication timeout on the RADIUS server, e.g. Cisco ISE.&amp;nbsp; This will force the client to re-authenticate.&amp;nbsp; These timers and your User-ID cache timeout should be similar.&lt;/P&gt;</description>
      <pubDate>Wed, 22 May 2024 22:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587708#M117242</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2024-05-22T22:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID timeout</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587721#M117244</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for the suggestions, I have figured out the issue however not sure how to fix it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So when an ip address is renewed when the dhcp lease runs out there is no logs for this on my access point so the user-id never gets notified.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This has only really been an issue for our ipads as they always stay connected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anyone else had an issue similar to this?&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 04:45:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-timeout/m-p/587721#M117244</guid>
      <dc:creator>MichaelSeddon</dc:creator>
      <dc:date>2024-05-23T04:45:49Z</dc:date>
    </item>
  </channel>
</rss>

