<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel' in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19535#M14267</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you have to enable User Identification, not only for identify your users in Inside but to enable VPN on Outside, it is mandatory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Apr 2012 10:10:11 GMT</pubDate>
    <dc:creator>ssancho</dc:creator>
    <dc:date>2012-04-09T10:10:11Z</dc:date>
    <item>
      <title>Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19534#M14266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get above machine when i try to commit. Os version is 4.1.3. Do i have to enable the user-identification on untrust interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Asanka &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2012 09:01:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19534#M14266</guid>
      <dc:creator>Asanka</dc:creator>
      <dc:date>2012-04-09T09:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19535#M14267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you have to enable User Identification, not only for identify your users in Inside but to enable VPN on Outside, it is mandatory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Samuel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Apr 2012 10:10:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19535#M14267</guid>
      <dc:creator>ssancho</dc:creator>
      <dc:date>2012-04-09T10:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19536#M14268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To clarify, the message is a 'Warning' and it can be disregarded if the GlobalProtect users do not need a user-ip-mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In most all environments you will want to enable the user-identification feature on the GlobalProtect zone to receive user-ip-mappings for logged in users. These mappings can be used for source user based policy and visualization in logging and reporting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2012 05:50:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19536#M14268</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-04-11T05:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19537#M14269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To further clarify - my understanding is that enable-user-identification on untrust is only required if you are using HIP profiles to control access for your GP users ? is that the only reason you would need to enable it ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2012 12:59:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19537#M14269</guid>
      <dc:creator>SimmSimm</dc:creator>
      <dc:date>2012-04-12T12:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19538#M14270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Thank you for the prompt response to my issue i've posed. In general what my major concern was if I enable user identification on Untrust interface just to get rid of the annoying warning message keeps popping up during the commit process, whether its going to add extra burden to the firewall by actively trying to resole internet addresses (Since its the Untrust interface) with my user-ip mappings stored on the appliance retrieved via active directory. I am pretty much confused why I am still getting this message even after I enable user identification to the Zone where my Global protect vpn tunnel bounded to.&lt;BR /&gt;&lt;BR /&gt;I am neither using HIP profiles to control users nor any other Global protect advanced features at the moment. But have configured Global protect to do authentication through a LDAP authentication profile which points to my AD.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA"&gt;Asanka&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 06:53:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19538#M14270</guid>
      <dc:creator>Asanka</dc:creator>
      <dc:date>2012-04-16T06:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19539#M14271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Asanka&lt;/P&gt;&lt;P&gt;I recommend not to enable to user-id on the untrust zone. This will have&amp;nbsp; impact on performance. I dont have a number to quantify this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;jerish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2012 17:15:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19539#M14271</guid>
      <dc:creator>jpa</dc:creator>
      <dc:date>2012-04-16T17:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19540#M14272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you Jerish for your comment. But please let me know how to get rid of the warning message i get when ever i do the commit without enabling it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Asanka&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 15:44:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19540#M14272</guid>
      <dc:creator>Asanka</dc:creator>
      <dc:date>2012-04-17T15:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19541#M14273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you do not enable UserID on the Untrust interface with GP enabled, you will be prompted with that warning message each time you commit. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you'd like get rid of the message, then you'd have to enable User Identification. It is your choice because without enabling UserID on the Untrust, you will be prompted with that Warning message each time&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 16:26:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19541#M14273</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2012-04-19T16:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19542#M14274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Would it be possible to implement some kind of "ignore these messages" so you wont get warnings you already know about (since a warning force you to read the commit popup just to find out you already knew that warning - compared to if no warning at all is displayed)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Along with somewhere in the GUI where one could see a list of ignored warnings (and be able to re-enable that warning again)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 19:56:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19542#M14274</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-04-19T19:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19543#M14275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;At this time, the warnings generated while doing a commit cannot be removed and would be readable each time you commit to the device.&lt;/P&gt;&lt;P&gt;Also there is no option to hide those warnings and re-enabling them.&lt;/P&gt;&lt;P&gt;The idea was to make the user aware of the&amp;nbsp; changes that were made to the configurations might impact the functionality.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&lt;/P&gt;&lt;P&gt;Parth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 21:12:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19543#M14275</guid>
      <dc:creator>ppatel</dc:creator>
      <dc:date>2012-04-19T21:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Warning: Zone 'Untrust' does not have 'enable-user-identification' turned on for globalprotect gateway 'tunnel'</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19544#M14276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had the exact same warning a few months back, what I did was enable user-identification on the untrust zone, but then also added 0.0.0.0/0 to the 'user-id excluded list' in the same window, this got rid of the error and also won't add load by trying to identify all untrust traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2012 13:35:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/warning-zone-untrust-does-not-have-enable-user-identification/m-p/19544#M14276</guid>
      <dc:creator>jrhjrh</dc:creator>
      <dc:date>2012-04-26T13:35:35Z</dc:date>
    </item>
  </channel>
</rss>

