<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Meru Integration with PANOS 6.1.5 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/meru-integration-with-panos-6-1-5/m-p/22018#M16072</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also just performed Meru user-ID integration.. testing and working on 6.1.5 and 6.1.6.. however does rely on Meru Smart Connect:&lt;/P&gt;&lt;P&gt;We limit the amount of information being sent to the PA devices once a user has successfully authenticated using a custom syslog message and then use Field Identifier value to extract the user-id information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;Meru uses Smart Connect for the on boarding, provides authentication and handles 802.1x profiles for the devices. From this Smart Connect device we setup syslog forwarding and configured Custom Message Format:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&lt;IMG __jive_id="20496" alt="meru smart connect.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20496_meru smart connect.png" style="width: 620px; height: 263px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;We limited the amount of information being sent to the PA devices using the format you can see in the above screenshot.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;Syslog Parsing Profile implemented on Palo:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&lt;IMG __jive_id="20497" alt="Palo parse.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20497_Palo parse.png" style="width: 620px; height: 390px;" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; Hope that helps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;Ben&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 30 Jul 2015 15:12:24 GMT</pubDate>
    <dc:creator>Ben-W</dc:creator>
    <dc:date>2015-07-30T15:12:24Z</dc:date>
    <item>
      <title>Meru Integration with PANOS 6.1.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meru-integration-with-panos-6-1-5/m-p/22016#M16070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Folks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're trying integrate our Meru system with Palo Alto Networks. but can't find any documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as i can see we have two options:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Radius&lt;/P&gt;&lt;P&gt;- Syslog feed straight to the PA device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone created the regex's / parsers for Meru and Syslog integration with Palo?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jul 2015 17:05:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meru-integration-with-panos-6-1-5/m-p/22016#M16070</guid>
      <dc:creator>MerchistonPA3020</dc:creator>
      <dc:date>2015-07-23T17:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Meru Integration with PANOS 6.1.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meru-integration-with-panos-6-1-5/m-p/22017#M16071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Chris,&lt;/P&gt;&lt;P&gt;I just completed this configuration. This is a syslog config with Meru's Captive Portal authentication.&lt;/P&gt;&lt;P&gt;PANOS 6.1.5, User-ID agent 6.0.2-3.&lt;/P&gt;&lt;P&gt;The only difference is I'm using a User-ID Agent rather than direct to the firewall, but both should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, we send the syslog to the User-ID agent (or firewall). &lt;/P&gt;&lt;P&gt;From Meru's Controller CLI :&amp;nbsp; &lt;STRONG&gt;syslog-host &amp;lt;IP address of User-ID agent or firewall&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two syslog entries that we can match on for Captive Portal, the request or success:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jul 29 08:25:05 10.246.116.208 xems: 1438172705l | security | info | CAP | Captive Portal User(myname@172.21.0.53) login Request Received. &lt;/P&gt;&lt;P&gt;Jul 29 08:25:06 10.246.116.208 SecurityMM: 1438172706l | security | info | CAP | myname@172.21.0.53 StationMac[7c:d1:c3:8d:4e:ea] Radius User logged in OK &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first log entry is pre-authentication on the Meru, so the second entry would be ideal to match on.&lt;/P&gt;&lt;P&gt;However, I have had difficulty matching the second entry, but no problem matching the first entry. (I probably need to use regex for the second one)&lt;/P&gt;&lt;P&gt;A failed login would still send a user-id mapping to the firewall, but still wouldn't allow the user past the Captive Portal, so we should be able to use it without issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, enable the syslog service in the agent setup. Then add a new filter.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="user-agent1-filter-setup.jpg" class="jive-image image-3" src="https://live.paloaltonetworks.com/legacyfs/online/20485_user-agent1-filter-setup.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To match the first log entry, create the following filter in the User-ID agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="user-agent1-filter.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20476_user-agent1-filter.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then create the syslog server listener referring to the name of the filter we created above.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="user-agent1-senderserver-setup.jpg" class="jive-image image-2" src="https://live.paloaltonetworks.com/legacyfs/online/20484_user-agent1-senderserver-setup.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Don't forget to commit the configuration on the agent!&lt;/P&gt;&lt;P&gt;The setup direct to the firewall should be similar.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following is the User-ID agent debug log for a successful login/mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 07/29/15 10:32:06:640[Debug&amp;nbsp; 372]: Syslog: Msg is '&amp;lt;38&amp;gt;xems: 1438180326l | security | info | CAP | Captive Portal User(myname@172.21.0.53) login Request Received.'&lt;/P&gt;&lt;P&gt; 07/29/15 10:32:06:640[Debug&amp;nbsp; 454]: Syslog: Discovered User (myname), Address (172.21.0.53) in tId (2432)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 07/29/15 10:32:06:640[Debug&amp;nbsp; 178]: UserIpMap: IP 172.21.0.53 with login name admin\myname and timeout 28800 is added. tId (2432)&lt;/P&gt;&lt;P&gt; 07/29/15 10:32:06:640[Debug 1039]: Syslog UDP: User (admin\myname), IP(172.21.0.53), Discovered at (1438180326), with Timeout (28800) tId(2432)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 07/29/15 10:32:06:640[Debug&amp;nbsp; 178]: UserIpMap: IP 172.21.0.53 with login name admin\myname and timeout 28800 is added. tId (2432)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 07/29/15 10:32:06:671[Debug&amp;nbsp; 242]: UserIpMap: IP (172.21.0.53) Username (admin\myname) queued for xmission to firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I create a filter for the success logon that works I'll add it, or perhaps someone else can! &lt;/P&gt;&lt;P&gt;Hopefully this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Miles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jul 2015 18:39:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meru-integration-with-panos-6-1-5/m-p/22017#M16071</guid>
      <dc:creator>mvonhausen</dc:creator>
      <dc:date>2015-07-29T18:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Meru Integration with PANOS 6.1.5</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/meru-integration-with-panos-6-1-5/m-p/22018#M16072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also just performed Meru user-ID integration.. testing and working on 6.1.5 and 6.1.6.. however does rely on Meru Smart Connect:&lt;/P&gt;&lt;P&gt;We limit the amount of information being sent to the PA devices once a user has successfully authenticated using a custom syslog message and then use Field Identifier value to extract the user-id information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;Meru uses Smart Connect for the on boarding, provides authentication and handles 802.1x profiles for the devices. From this Smart Connect device we setup syslog forwarding and configured Custom Message Format:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt; &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&lt;IMG __jive_id="20496" alt="meru smart connect.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20496_meru smart connect.png" style="width: 620px; height: 263px;" /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;We limited the amount of information being sent to the PA devices using the format you can see in the above screenshot.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;Syslog Parsing Profile implemented on Palo:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #1f497d; font-size: 12pt; font-family: Calibri;"&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&lt;IMG __jive_id="20497" alt="Palo parse.png" class="image-1 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20497_Palo parse.png" style="width: 620px; height: 390px;" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; Hope that helps&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;Ben&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jul 2015 15:12:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/meru-integration-with-panos-6-1-5/m-p/22018#M16072</guid>
      <dc:creator>Ben-W</dc:creator>
      <dc:date>2015-07-30T15:12:24Z</dc:date>
    </item>
  </channel>
</rss>

