<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID - issues with mapping from Juniper Mist wireless in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/649844#M122163</link>
    <description>&lt;P&gt;Hello.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have issues with mapping user from Juniper Mist. User-ID is set and working fine when monitoring LAN traffic. But when I want to check wireless users I don't see Source User. From my research I understand I need some type of "bridge" between Juniper Mist and Panorama in form on syslog.&amp;nbsp;&lt;BR /&gt;Sadly both systems are supported by separate companies so I cant ask them for help in this case.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Do anyone here have similar issue in past with Juniper Mist and Panorama? And give me any clue where I need to dig for information? Or which syslog (open source will be best) I can use as "bridge" between those two systems?&lt;BR /&gt;&lt;BR /&gt;Thank you for any advices&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2024 15:41:11 GMT</pubDate>
    <dc:creator>ParticularNoobie</dc:creator>
    <dc:date>2024-11-22T15:41:11Z</dc:date>
    <item>
      <title>User-ID - issues with mapping from Juniper Mist wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/649844#M122163</link>
      <description>&lt;P&gt;Hello.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have issues with mapping user from Juniper Mist. User-ID is set and working fine when monitoring LAN traffic. But when I want to check wireless users I don't see Source User. From my research I understand I need some type of "bridge" between Juniper Mist and Panorama in form on syslog.&amp;nbsp;&lt;BR /&gt;Sadly both systems are supported by separate companies so I cant ask them for help in this case.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Do anyone here have similar issue in past with Juniper Mist and Panorama? And give me any clue where I need to dig for information? Or which syslog (open source will be best) I can use as "bridge" between those two systems?&lt;BR /&gt;&lt;BR /&gt;Thank you for any advices&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:41:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/649844#M122163</guid>
      <dc:creator>ParticularNoobie</dc:creator>
      <dc:date>2024-11-22T15:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - issues with mapping from Juniper Mist wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/649873#M122166</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190045"&gt;@ParticularNoobie&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;How are you authenticating users on the Juniper side of things? If you're using RADIUS for authentication you could just pull logs from your RADIUS server(s) directly. It's possible that you don't actually need to utilize SYSLOG scrapping depending on your authentication setup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do require syslog scrapping you don't actually need to have any sort of intermediate solution. You can send SYSLOG directly to Panorama with additional information available &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/user-id/map-ip-addresses-to-users/configure-user-id-to-monitor-syslog-senders-for-user-mapping/configure-the-pan-os-integrated-user-id-agent-as-a-syslog-listener#id91eb3abd-43c1-4969-8a5f-df032685e277" target="_self"&gt;HERE&lt;/A&gt;. You can also use an intermediate solution like Graylog as an open-source example that you can then have configured to update user mappings through the API easily as well. If you don't already have that setup just enabling the firewall as a listener is a more straight-forward solution however.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 15:53:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/649873#M122166</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-11-22T15:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - issues with mapping from Juniper Mist wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/649901#M122168</link>
      <description>&lt;P&gt;Thank you for response BPry.&lt;BR /&gt;Both systems pulling info from this same Radius. That (with my knowledge) its strange. Juniper auth users by Windows AD (Radius) I can log into server and check users IP/Username for wifi. LAN users using this same Windows AD (Radius) for access desktops (docked laptops). And also I can of course log into this same server and check second vlan and see IP/Username of those users.&lt;BR /&gt;&lt;BR /&gt;But Panorama showing only LAN users, and ignoring all Juniper/Wifi users.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Idea about syslog server was put in my head after conversation (with many long mails with screenshots and few life session when I explaining what is where or exactly what is missing) with our PaloAlto support as "only solution".&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I hope that will bring more light on this case.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 16:07:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/649901#M122168</guid>
      <dc:creator>ParticularNoobie</dc:creator>
      <dc:date>2024-11-22T16:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - issues with mapping from Juniper Mist wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/651724#M122179</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/190045"&gt;@ParticularNoobie&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sorry to chime in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Based on my past experience, Mist does not send username unless Radius accounting is enabled under: Site &amp;gt; Wireless &amp;gt; WLANs &amp;gt; [SSID name] &amp;gt;&amp;nbsp;RADIUS Authentication Servers. Reference:&amp;nbsp;&lt;A href="https://www.juniper.net/documentation/us/en/software/mist/mist-wireless/topics/topic-map/radius-attributes.html" target="_blank"&gt;https://www.juniper.net/documentation/us/en/software/mist/mist-wireless/topics/topic-map/radius-attributes.html&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2024 07:29:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/651724#M122179</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2024-11-25T07:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - issues with mapping from Juniper Mist wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/847197#M122235</link>
      <description>&lt;P&gt;Maybe I barking on wrong tree.&lt;BR /&gt;&lt;BR /&gt;Maybe syslog server is not need. And only what I need is a)change PaloAlto support company &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; b) change settings on Group Mapping.&lt;BR /&gt;&lt;BR /&gt;When I start cash I noticed that this same users (auth by GroupPolicy) sometimes are visible.. sometimes are not.&lt;BR /&gt;In other case - all users from BYOD network (auth by radius but with manual username/password) are not visible at all.&lt;BR /&gt;&lt;BR /&gt;Maybe someone can help in this case?&lt;BR /&gt;&lt;BR /&gt;I attaching screenshot created today with that issue.&lt;BR /&gt;One user, one computer, one destination - and we have smoke and mirrors case.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 16:01:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/847197#M122235</guid>
      <dc:creator>ParticularNoobie</dc:creator>
      <dc:date>2024-11-27T16:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - issues with mapping from Juniper Mist wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/1239221#M125255</link>
      <description>&lt;P&gt;Hello, sorry for the necro post, I'm trying to do the same, and found this 3rd party API called Pan RA proxy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://github.com/lithnet/pan-ra-proxy" target="_blank"&gt;https://github.com/lithnet/pan-ra-proxy&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Has anyone had success running it using local radius along with a cloud ap like Mist and the PAN firewall?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advanced.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 17:52:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-issues-with-mapping-from-juniper-mist-wireless/m-p/1239221#M125255</guid>
      <dc:creator>cdcirexx</dc:creator>
      <dc:date>2025-10-01T17:52:33Z</dc:date>
    </item>
  </channel>
</rss>

