<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: source user showing as unknown in traffic monitor in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19933#M14534</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you use wmi probing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you see with the following command: debug user-id dump probing-stats&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use probing and it fails three times to get a user from the client, the already mapped user will be deleted for the IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Feb 2015 14:13:52 GMT</pubDate>
    <dc:creator>Wenar</dc:creator>
    <dc:date>2015-02-12T14:13:52Z</dc:date>
    <item>
      <title>source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19925#M14526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 15px;"&gt;Found an issue on a customer's firewall.&amp;nbsp; For some reason, the “source user” becomes unknown while students are using a web application called Istation.&amp;nbsp; When that happens, the web traffic for that IP address becomes blocked by another policy.&amp;nbsp; She wrote a specific policy for Istation traffic even if the user is unknown to resolve this issue.&amp;nbsp;&amp;nbsp; But the real question is….Why is the “source user” blanking out in the middle of using a web application?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 15px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 15px;"&gt;Appreciate your thoughts and suggestions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri, sans-serif; font-size: 15px;"&gt;Thanks&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2015 17:50:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19925#M14526</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2015-02-03T17:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19926#M14527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm fighting a similar issue on my side especially with users on VPN getting the wrong web-filtering policy. I have not seen the 'unknown' source user, its usually just he username on the VPN without the domain (in my case so this is why they get the wrong policy). Support did provide guidance on this for me, perhaps they can do the same for you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another thing that just occurred to me, how many user-id agents are you using or are you using the PAN's for the direct lookup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2015 19:19:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19926#M14527</guid>
      <dc:creator>oklier</dc:creator>
      <dc:date>2015-02-03T19:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19927#M14528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;haven't opened a case yet...we may try to upgrade to at least 6.0.7 and see if that helps. The agent is installed on one server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2015 21:14:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19927#M14528</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2015-02-03T21:14:27Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19928#M14529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would say depending on the size of the environment including AD, I would recommend bumping that number up to maybe two or three. That way if one is not responding or up, you have something to refer to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Feb 2015 21:17:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19928#M14529</guid>
      <dc:creator>oklier</dc:creator>
      <dc:date>2015-02-03T21:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19929#M14530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple of my customers hit similar issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does your firewall run over 388 days?&lt;/P&gt;&lt;P&gt;There is one fixed issue which is bug#64166. (you can find it in 5.0.14 RN or 6.0.4 RN.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Feb 2015 02:37:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19929#M14530</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2015-02-04T02:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19930#M14531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like the user is caching out. Nothing to do with the application. I'm assuming these computers are part of the domain since you do pick up the user initially through the user-ID agent. Did you enable "Server session monitoring" in the userID agent? Also is WMI probing enabled and working? Both these mechanisms will help keep the user to IP mappings fresh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Feb 2015 16:06:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19930#M14531</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2015-02-05T16:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19931#M14532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@emr-the box has not been up that long. Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@Quinton- not sure on the session monitoring..I will check. Will also check WMI probing. How would I know if it is working or not?? These are actually wireless users, if that matters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Feb 2015 19:28:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19931#M14532</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2015-02-11T19:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19932#M14533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wireless is no problem. Are these devices part of the Windows domain? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2015 10:49:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19932#M14533</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2015-02-12T10:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: source user showing as unknown in traffic monitor</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19933#M14534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you use wmi probing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you see with the following command: debug user-id dump probing-stats&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you use probing and it fails three times to get a user from the client, the already mapped user will be deleted for the IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2015 14:13:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-showing-as-unknown-in-traffic-monitor/m-p/19933#M14534</guid>
      <dc:creator>Wenar</dc:creator>
      <dc:date>2015-02-12T14:13:52Z</dc:date>
    </item>
  </channel>
</rss>

