<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there anything in the works for pulling User-ID data directly from a MS NPS server in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16558#M12074</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, I might have to look into that scripting solution. I'd definitely prefer native NPS integration, but who wouldn't? I just wonder if it's in the pipeline.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Aug 2014 16:12:09 GMT</pubDate>
    <dc:creator>JordanGoodnough</dc:creator>
    <dc:date>2014-08-05T16:12:09Z</dc:date>
    <item>
      <title>Is there anything in the works for pulling User-ID data directly from a MS NPS server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16554#M12070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;User-ID integration with Microsoft AD is great, and works nicely, but we have the bulk of our users using RADIUS to authenticate wirelessly with 802.1x, and we're using a Microsoft NPS server to do that job. These users' devices are not necessarily (and often are not) Windows domain computers, so the LDAP lookups aren't providing the needed information for a User-ID mapping. Is there any good way to get that information from the NPS server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Aug 2014 18:10:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16554#M12070</guid>
      <dc:creator>JordanGoodnough</dc:creator>
      <dc:date>2014-08-04T18:10:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anything in the works for pulling User-ID data directly from a MS NPS server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16555#M12071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At the moment there isn't direct intergration with NPS however new features in PAN OS 6.0 called "User-ID Integration With Syslog" could be usefull for You.&lt;/P&gt;&lt;P&gt;Please read &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6602"&gt;New Features Guide 6.0 (English)&lt;/A&gt; page 96&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Aug 2014 20:11:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16555#M12071</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-04T20:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anything in the works for pulling User-ID data directly from a MS NPS server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16556#M12072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One problem you might encounter with userid integration is that the ip in the Microsoft NPS logs is not the ip address of the client machine but the device performing the radius Auth on behalf of client.&lt;/P&gt;&lt;P&gt;If the wireless device is capable of sending user and ip information in syslog format then you can use new feature in Pan-OS 6.0 mentioned above.&lt;/P&gt;&lt;P&gt;If the device is not able to send this information in syslog such as Cisco WLC (which uses SNMP) then would need to have the information sent to SNMP collector from WLC.&lt;/P&gt;&lt;P&gt;On the SNMP collector would need to have a way of parsing the event and forwarding that to Pan User-ID for User-ID integration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Aug 2014 22:07:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16556#M12072</guid>
      <dc:creator>dmaynard</dc:creator>
      <dc:date>2014-08-04T22:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anything in the works for pulling User-ID data directly from a MS NPS server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16557#M12073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could configure captive portal.&amp;nbsp; But I guess you don't want to force a login portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue with RADIUS is as &lt;A href="https://live.paloaltonetworks.com/u1/23836"&gt;dmaynard&lt;/A&gt; says, the ip association is in the payloads.&amp;nbsp; There is a script posted in Dev center to extract this for user id association.&amp;nbsp; I'm not sure how well it works as I haven't used it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4730"&gt;Scripting solution for User ID working with Microsoft IAS/NPS&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 01:09:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16557#M12073</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-05T01:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anything in the works for pulling User-ID data directly from a MS NPS server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16558#M12074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yeah, I might have to look into that scripting solution. I'd definitely prefer native NPS integration, but who wouldn't? I just wonder if it's in the pipeline.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 16:12:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16558#M12074</guid>
      <dc:creator>JordanGoodnough</dc:creator>
      <dc:date>2014-08-05T16:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: Is there anything in the works for pulling User-ID data directly from a MS NPS server</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16559#M12075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roadmap questions are only answered under the NDA from your Sales team.&amp;nbsp; They can also see if there is an existing FR (Feature Request) for the functionality.&amp;nbsp; If there is an FR number you can add a "vote" for the feature.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Aug 2014 21:55:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/is-there-anything-in-the-works-for-pulling-user-id-data-directly/m-p/16559#M12075</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2014-08-05T21:55:22Z</dc:date>
    </item>
  </channel>
</rss>

