<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID Agent identifies local PC users so captive portal never kicks in? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21457#M15666</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but I don't see anything in those that leaps out as being applicable here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're not even seeing the portal - the PAN seems to assume the username is "&lt;STRONG&gt;LOCALPC\localaccount&lt;/STRONG&gt;" so simply blocks access because it doesn't match any rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Jan 2014 18:56:01 GMT</pubDate>
    <dc:creator>networkadmin</dc:creator>
    <dc:date>2014-01-29T18:56:01Z</dc:date>
    <item>
      <title>User-ID Agent identifies local PC users so captive portal never kicks in?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21455#M15664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I upgraded our PAN from 4.1.x to 5.0.10 and also upgraded the User-ID agent from 3.x to the latest 5.x.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have some rules configured with groups specified and we have captive portal in place and what used to happen was if you came along on a domain joined laptop but were logged on as a local account (so &lt;EM&gt;&lt;STRONG&gt;LAPTOPNAME\LocalAccount&lt;/STRONG&gt;&lt;/EM&gt;) you'd get the portal and would have to authenticate using a domain account (standard Kerberos auth against the DCs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's happening now is that the request is blocked because it's hitting the last whitelist rule which blocks all URL Categories other than the allow whitelist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The block page is showing the user as &lt;EM&gt;&lt;STRONG&gt;LAPTOPNAME\LocalAccount&lt;/STRONG&gt;&lt;/EM&gt; so the firewall must be picking up the local logon name from the User-ID agent - looking at the mapping list on the User-ID agent on the DCs confirms this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'm assuming we don't get the captive portal because the user is always known so the portal never needs to kick in?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I make it so that the firewall won't see any usernames other than &lt;STRONG&gt;&lt;EM&gt;DOMAIN\Username&lt;/EM&gt;&lt;/STRONG&gt; from the User-ID agent please, so that in the situation above the portal would kick in like it used to?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've looked everywhere I can think of and I'm drawing a blank.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 16:47:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21455#M15664</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-01-29T16:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent identifies local PC users so captive portal never kicks in?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21456#M15665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Related discussions:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/5140"&gt;password&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/21970"&gt;Re: Captive Portal to Internal Servers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 18:37:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21456#M15665</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-01-29T18:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent identifies local PC users so captive portal never kicks in?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21457#M15666</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, but I don't see anything in those that leaps out as being applicable here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're not even seeing the portal - the PAN seems to assume the username is "&lt;STRONG&gt;LOCALPC\localaccount&lt;/STRONG&gt;" so simply blocks access because it doesn't match any rule.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 18:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21457#M15666</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-01-29T18:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent identifies local PC users so captive portal never kicks in?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21458#M15667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following docs will help:-&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/message/20368#20368"&gt;https://live.paloaltonetworks.com/message/20368#20368&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-3629"&gt;https://live.paloaltonetworks.com/docs/DOC-3629&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 20:17:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21458#M15667</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2014-01-29T20:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent identifies local PC users so captive portal never kicks in?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21459#M15668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It looks similar to the second issue.&amp;nbsp; We have a standard AD though at 2003 Functional Level - nothing unusual or custom so this seems bizarre behaviour.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jan 2014 11:08:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-identifies-local-pc-users-so-captive-portal-never/m-p/21459#M15668</guid>
      <dc:creator>networkadmin</dc:creator>
      <dc:date>2014-01-30T11:08:01Z</dc:date>
    </item>
  </channel>
</rss>

