<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA with proxy, user logging in traffic log in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-proxy-user-logging-in-traffic-log/m-p/19609#M14327</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following document for more information.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1128"&gt;Enabling support for the  X-Forwarded-For HTTP header&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Jan 2015 15:49:08 GMT</pubDate>
    <dc:creator>hshah</dc:creator>
    <dc:date>2015-01-30T15:49:08Z</dc:date>
    <item>
      <title>PA with proxy, user logging in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-proxy-user-logging-in-traffic-log/m-p/19608#M14326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we’re running the following setup on PAN-OS is 6.1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="text-align: left; padding-left: 30px;"&gt;client-pc|pa-dmz|proxy|internet&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;citrix-server|pa-dmz|proxy|internet&lt;/P&gt;&lt;P&gt;User-ID Agent is collecting IP&amp;gt;User mapping.&lt;/P&gt;&lt;P&gt;We’re logging only Deny events in the traffic log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We want to achieve the following:&lt;/P&gt;&lt;P&gt;When User A tries to open a website/app which is not allowed, we want to see in the traffic log the username and source IP address. The source IP is coming up with x-ff-header, but not the user; even if PA knows that User A has this specific IP address.&lt;/P&gt;&lt;P&gt;The reason is easy: We’re an almost Citrix-only shop, so IP logging only is not that helpful in this case. We could install the Citrix User-ID Agent, but at this stage even the username is not displayed when trying with a client-pc, so first things first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A workaround that could work is the following: Enable logging for connection start (that shows the users) through proxy and check directly following entries for deny. Bu honestly, this might work for a handful user not for 700+ and that’s not very efficient.&lt;/P&gt;&lt;P&gt;I believe our setup is not that exotic, so we’re not the first customers who’re running into this. Maybe I just don’t see the right way… How did you solved this? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this stage we’ve not purchased an URL-Filter license. We don’t want to oversee the users, just want to have an easy way to troubleshoot connection problems to websites; as with App-ID everything is blocked, what isn’t explicitly allowed this could become some hard times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for helping!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2015 11:02:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-proxy-user-logging-in-traffic-log/m-p/19608#M14326</guid>
      <dc:creator>Sven_Lieckfeldt</dc:creator>
      <dc:date>2015-01-30T11:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: PA with proxy, user logging in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-proxy-user-logging-in-traffic-log/m-p/19609#M14327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following document for more information.&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1128"&gt;Enabling support for the  X-Forwarded-For HTTP header&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2015 15:49:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-proxy-user-logging-in-traffic-log/m-p/19609#M14327</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2015-01-30T15:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: PA with proxy, user logging in traffic log</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-with-proxy-user-logging-in-traffic-log/m-p/19610#M14328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your answer. Unfortunately xff doesn't solve our problem at all.&lt;/P&gt;&lt;P&gt;We are able to map clientip to user, but that doesn't do the trick on the Citrix server; where 50 users share the same IP address. Also, with xff the User-ID Agent data is not used in the Traffic Log, which isn't really handy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following approach seems to be feasible for us:&lt;/P&gt;&lt;P&gt;Allowing the same websites/applications on the border from internal-lan to DMZ, as the proxy has, gives us the possibility to see who has tried to access a website. In this scenario the User-ID Agent does work, because the connection is established first by the Citrix server and after then handed over to the proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Feb 2015 08:55:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-with-proxy-user-logging-in-traffic-log/m-p/19610#M14328</guid>
      <dc:creator>Sven_Lieckfeldt</dc:creator>
      <dc:date>2015-02-10T08:55:24Z</dc:date>
    </item>
  </channel>
</rss>

