<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User ID Anomalies in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/604258#M119934</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a strange behaviour with some user on user ID. We have 2 site A and B and our firewall have the mapping from the same agent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we found that user1 access site A and user2 access site B.&lt;/P&gt;
&lt;P&gt;issue that we found that user1 is access site B using the user2 IP.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DennyChanditya_0-1729151292634.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63006iE104290980EC4CDE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DennyChanditya_0-1729151292634.png" alt="DennyChanditya_0-1729151292634.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We check on each site the mapping is fine, but we dont find the user1 mapping to IP user2 on all firewall.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DennyChanditya_1-1729151338014.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63007i95B4137D08CF2211/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DennyChanditya_1-1729151338014.png" alt="DennyChanditya_1-1729151338014.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we check on User ID logs GUI and CLI it dont have any history about user1 was mapping to IP that user2 is using.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any clue where i can find this data related to user id mapping, because i was use all the CLI command but didn't find the information that&amp;nbsp;user1 was mapping to IP user2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Oct 2024 07:49:03 GMT</pubDate>
    <dc:creator>DennyChanditya</dc:creator>
    <dc:date>2024-10-17T07:49:03Z</dc:date>
    <item>
      <title>User ID Anomalies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/604258#M119934</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I had a strange behaviour with some user on user ID. We have 2 site A and B and our firewall have the mapping from the same agent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we found that user1 access site A and user2 access site B.&lt;/P&gt;
&lt;P&gt;issue that we found that user1 is access site B using the user2 IP.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DennyChanditya_0-1729151292634.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63006iE104290980EC4CDE/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DennyChanditya_0-1729151292634.png" alt="DennyChanditya_0-1729151292634.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We check on each site the mapping is fine, but we dont find the user1 mapping to IP user2 on all firewall.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DennyChanditya_1-1729151338014.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/63007i95B4137D08CF2211/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DennyChanditya_1-1729151338014.png" alt="DennyChanditya_1-1729151338014.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we check on User ID logs GUI and CLI it dont have any history about user1 was mapping to IP that user2 is using.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any clue where i can find this data related to user id mapping, because i was use all the CLI command but didn't find the information that&amp;nbsp;user1 was mapping to IP user2.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks before.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 07:49:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/604258#M119934</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2024-10-17T07:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Anomalies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/606699#M120368</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/187777"&gt;@DennyChanditya&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;Looks like you're using XFF for mapping which complicates things. You might want to spend some time with&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-policies-and-logging-source-users" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/use-xff-values-for-policies-and-logging-source-users&lt;/A&gt;&amp;nbsp;more specifically&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs#id1bc409ba-74ba-4402-8480-ffa128542926" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/policy/identify-users-connected-through-a-proxy-server/add-xff-values-to-url-filtering-logs#id1bc409ba-74ba-4402-8480-ffa128542926&lt;/A&gt;&amp;nbsp;mentioned on that page.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 23:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/606699#M120368</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-10-17T23:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Anomalies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/606750#M120399</link>
      <description>&lt;P&gt;We are not using XFF Configuration, only user ID from the agent, issue here we didnt find the mapping for specific user on user-id logs even no history about it. but on traffic log it shows the IP is&amp;nbsp; used by that source user&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 04:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/606750#M120399</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2024-10-18T04:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Anomalies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/615707#M121843</link>
      <description>&lt;P&gt;Still not getting update until now, already opencase&lt;/P&gt;
&lt;P&gt;we found that in one session, it was different logs from Traffic log GUI and CLI&lt;BR /&gt;from GUI it was incorrect mapping ip and user, but in CLI it was correct mapping for ip and user.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;userid agent and user id logs is fine, they have the right mapping, but only in the traffic logs&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 03:44:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/615707#M121843</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2024-10-30T03:44:45Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Anomalies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/615768#M121852</link>
      <description>&lt;P&gt;What code are you running? We ran into an issue where ID mapping wasn't correct on 3410s running 10.2.7, it was identified as &lt;SPAN&gt;PAN-239366.&amp;nbsp; Maybe you're hitting this bug?&amp;nbsp; A reboot of firewalls was needed to get the mapping to show correctly.&amp;nbsp; There was also a debug command which could be ran in-lieu-of the reboot, but my suggestion is to confirm with TAC your issue could be related to this bug.&amp;nbsp; If it is they can also provide a work around.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I think 10.2.10-h4 fixes this bug, TAC can also confirm this.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 13:09:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/615768#M121852</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2024-10-30T13:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: User ID Anomalies</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/626213#M122082</link>
      <description>&lt;P&gt;Im usngi PA5220, with 10.2.9-h1, as the last activity we do the restart log-receiver on the firewall as per TAC said.&lt;/P&gt;
&lt;P&gt;still dont know what cause this, but so far the uid agent mapping and users on log traffic is correct.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;we still monitoring until now, because we found out that the traffic&amp;nbsp; log from GUI and CLI is different for showing the source users.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Nov 2024 08:19:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-anomalies/m-p/626213#M122082</guid>
      <dc:creator>DennyChanditya</dc:creator>
      <dc:date>2024-11-19T08:19:32Z</dc:date>
    </item>
  </channel>
</rss>

