<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source user not found in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22356#M16300</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another situation can be that userX is logged in but needs assistence from the support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Support logins using RDP (through SCOM or such) as userY to remotely assist userX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now userY is the latest logged in to this device and suddently userX lost all its credentials in the network until the userX relogins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is this handled some way today (because one ip can only have one user if im not mistaken in the userid-db)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 Nov 2012 07:15:03 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-11-01T07:15:03Z</dc:date>
    <item>
      <title>Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22350#M16294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a random issue occur whereby one or two of my users seem to loose access to their internet privileges. I check on PA and it shows the traffic but no source user, which is what the rule for their internet access is based on. If we reboot their pc then it is fine again, but I just wondered what could be causing this to all of a sudden and randomally not identify their user.&lt;/P&gt;&lt;P&gt;I have checked and they are not running any applications with elevated permissions. So just wondered if this is something anyone else has come across or knows how to resolve?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, I have a PA 2020 box and 2 User identification servers running. Both online.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2012 15:19:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22350#M16294</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2012-10-26T15:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22351#M16295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is your settings of the pan-agent installations you run?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything from TTL's to if serverlogs are being followed along with wmi query of the clients?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Oct 2012 21:00:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22351#M16295</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-10-26T21:00:10Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22352#M16296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mikand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My settings on my PAN-Agents are as follows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enabled Security Log monitor. 1 Sec&lt;/P&gt;&lt;P&gt;Enable Server Session Read Frequency was off but I now have it on as 10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enabled WMI probing&lt;/P&gt;&lt;P&gt;Enabled NetBIOS Probing. 1 minute Interval&lt;/P&gt;&lt;P&gt;Enabled User Identification Timeout 45 min&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And Use SSL is the only other option ticked in my settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 09:00:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22352#M16296</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2012-10-30T09:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22353#M16297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using an Agent, like User-ID agent, the agent has a "timeout" period where it will timeout the user who is logged in..&amp;nbsp; (I think 45 min default), might be longer.&lt;/P&gt;&lt;P&gt;After this timeout, the user's ID will be unknown, and at that time you can reboot/login again, this action should tell the AD server that the account has logged back in, thus updating the user information, thus Identifying the user. But there are really 2 answers:&lt;/P&gt;&lt;P&gt;1. Extend the user timeout, so the user's information will be in the cache longer and they will no be logged "out".&lt;/P&gt;&lt;P&gt;2. Setup and configure Captive Portal, so when users who are "unknown" are then prompted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this does not help, please open a case with support and we can assist that way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have a Great Day!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2012 19:27:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22353#M16297</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-10-30T19:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22354#M16298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will try increase the timeout to see if that resolves it. Is there any harm in turning off that timeout? Ie: if someone logs on with a user with extended privileges and then logs off, then someone logs onto that pc locally, if I have turned the timeout off will they get the previous users web permissions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As with Captive Portal, this was in use previously, but we are trying to move away from that in lieu of running our rules based on domain credentials. Hence my captive portal is currently disabled. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 08:33:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22354#M16298</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2012-10-31T08:33:06Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22355#M16299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your question:&lt;/P&gt;&lt;P&gt;"if someone logs on with a user with extended privileges and then logs off, then someone logs onto that pc locally, if I have turned the timeout off will they get the previous users web permissions?"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the first user does not log off, then yes.&lt;/P&gt;&lt;P&gt;If the first logs out, then someone else logs in, there should be a system log that indicates that someone is logging in, and adjust the user info as needed.&lt;/P&gt;&lt;P&gt;If this is traffic on a Terminal server, where multiple people are logged into the same machine, then you would need to think about using the Terminal Services Agent.&lt;/P&gt;&lt;P&gt;Either way, You always want to have some level of "timeout".. be it 3-4-5 hours.. but the longer that you keep someone in the system..&amp;nbsp; As you would never want someone to be &lt;/P&gt;&lt;P&gt;logged into a machine for "infinity".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can understand about Captive Portal. It makes sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Oct 2012 13:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22355#M16299</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-10-31T13:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22356#M16300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Another situation can be that userX is logged in but needs assistence from the support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Support logins using RDP (through SCOM or such) as userY to remotely assist userX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now userY is the latest logged in to this device and suddently userX lost all its credentials in the network until the userX relogins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is this handled some way today (because one ip can only have one user if im not mistaken in the userid-db)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 07:15:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22356#M16300</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-11-01T07:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Source user not found</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22357#M16301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I have noticed that with the multi remote and when another userY logs on the currently logged on User X gets their permissions. Although I have made my own support team aware of this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I thought having the Client Probing set to 1 minute it means that they wouldn't have those extended permissions for very log after the userY logs off. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Nov 2012 09:03:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/source-user-not-found/m-p/22357#M16301</guid>
      <dc:creator>JRussell</dc:creator>
      <dc:date>2012-11-01T09:03:13Z</dc:date>
    </item>
  </channel>
</rss>

