<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User Agent and Active Directory 2008 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1839#M1365</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you logging succes and failures for the "audit account logon events" and "audit logon events' on the domain controllers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Apr 2011 12:51:03 GMT</pubDate>
    <dc:creator>mharding</dc:creator>
    <dc:date>2011-04-05T12:51:03Z</dc:date>
    <item>
      <title>User Agent and Active Directory 2008</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1838#M1364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like to know if there are some known issues about communications between useragent and AD2008 ?&lt;/P&gt;&lt;P&gt;We are migrating from AD2003 to AD2008 and some User-ID associations are missed :smileyangry:&lt;/P&gt;&lt;P&gt;We are not using security logs at the moment but only the session table monitoring.&lt;/P&gt;&lt;P&gt;We already have opened&amp;nbsp; a case but I would like to share this experience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We also encountered some issues with Juniper Firewall and AD2008. The ALG MS-RPC features based on UUID matching no longer works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the UUID used by Palo Alto agents when communicating with the AD ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2011 04:32:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1838#M1364</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-04-05T04:32:51Z</dc:date>
    </item>
    <item>
      <title>Re: User Agent and Active Directory 2008</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1839#M1365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you logging succes and failures for the "audit account logon events" and "audit logon events' on the domain controllers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Apr 2011 12:51:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1839#M1365</guid>
      <dc:creator>mharding</dc:creator>
      <dc:date>2011-04-05T12:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: User Agent and Active Directory 2008</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1840#M1366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, not yet. We plan to do it with AD2008. We do not anderstand why some identification are missed now ( 2008 vs 2003 ).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2011 02:59:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1840#M1366</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-04-06T02:59:54Z</dc:date>
    </item>
    <item>
      <title>Re: User Agent and Active Directory 2008</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1841#M1367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The root cause of this issue starts becoming more accurate :&lt;/P&gt;&lt;P&gt;When an anonymous event comes from a user PC to the DC ( which has already been recognized by the AD agent ), here is the behaviour :&lt;/P&gt;&lt;P&gt;With DC2003, the AD agent get the field "sesi10_username" with an empty value, which has no effect on the Pan Agent.&lt;/P&gt;&lt;P&gt;With DC2008R2, the AD agent get the field "sesi10_username" with the value ANONYMOUS LOGON, which cause the PAN agent to overwrite the previous UserID-IP identification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, how to turn around this issue ? Is there a way on the agent to ignore ANONYMOUS LOGON ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 May 2011 15:50:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1841#M1367</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-05-26T15:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: User Agent and Active Directory 2008</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1842#M1368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;bdaussin wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The root cause of this issue starts becoming more accurate :&lt;/P&gt;&lt;P&gt;When an anonymous event comes from a user PC to the DC ( which has already been recognized by the AD agent ), here is the behaviour :&lt;/P&gt;&lt;P&gt;With DC2003, the AD agent get the field "sesi10_username" with an empty value, which has no effect on the Pan Agent.&lt;/P&gt;&lt;P&gt;With DC2008R2, the AD agent get the field "sesi10_username" with the value ANONYMOUS LOGON, which cause the PAN agent to overwrite the previous UserID-IP identification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, how to turn around this issue ? Is there a way on the agent to ignore ANONYMOUS LOGON ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the Palo Alto agent directory, create a file called "ignore_user_list.txt"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add your "ANONYMOUS LOGON" to this file - you may need to put it in quotes, like I jsut did, as there is a space in the username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if this works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 May 2011 23:18:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1842#M1368</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2011-05-29T23:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: User Agent and Active Directory 2008</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1843#M1369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your advice and workaround. We set up this file on the AD agent, but it seems that it filters out all informations coming from the DC session table &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have opened a case to the support but it's quite long to get a usefull answer :smileyangry:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2011 12:36:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-agent-and-active-directory-2008/m-p/1843#M1369</guid>
      <dc:creator>bdaussin</dc:creator>
      <dc:date>2011-06-07T12:36:41Z</dc:date>
    </item>
  </channel>
</rss>

