<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID agent collecting non-domain user-ip mappings in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23474#M17120</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just tried what you suggested: with client probing disabled, no ip mapping is done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way I can filter out WMI probing for non-domain users, but keep it for our domain users ? We need probing because we have some turnaround...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 07 Oct 2013 10:57:20 GMT</pubDate>
    <dc:creator>dieter_b</dc:creator>
    <dc:date>2013-10-07T10:57:20Z</dc:date>
    <item>
      <title>User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23469#M17115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;User-ID agent version 5.0.6-6 seems to collect non-domain user to ip mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact this is a laptop that is a member of our domain, but I'm logging on with a local administrator. User-ID agent collects it and maps the ip to "hostname\administrator" (as opposed to normal mappings "domainname\username"). User-ID debug logs show it being collected because of the computer account ( DOMAINNAME\hostname$ ) logged on to the domain.&lt;/P&gt;&lt;P&gt;As expected, the user is denied access to websites (Application block page), because he doesn't belong to the allowed AD groups. The user is not even given a CP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In version 3.1.2 this does not occur and you can actually limit it from collecting those:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;under Configure you can enter a domain name&lt;/LI&gt;&lt;LI&gt;under Filter Group Members you can filter out unwanted AD groups (like domain computers)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I can't find any of these in the new agent...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most annoying, what can I do to change this behaviour ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Oct 2013 14:54:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23469#M17115</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-03T14:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23470#M17116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone else seen this behaviour ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 08:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23470#M17116</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-07T08:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23471#M17117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Probing is enabled ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 08:28:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23471#M17117</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-07T08:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23472#M17118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, WMI probing. Would that be te reason a non-domain user is mapped ?&lt;/P&gt;&lt;P&gt;Then how can I prevent non-domain users from being collected ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 09:28:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23472#M17118</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-07T09:28:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23473#M17119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try if issue is resolved when probing is off&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 10:44:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23473#M17119</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-07T10:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23474#M17120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just tried what you suggested: with client probing disabled, no ip mapping is done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way I can filter out WMI probing for non-domain users, but keep it for our domain users ? We need probing because we have some turnaround...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 10:57:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23474#M17120</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-07T10:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23475#M17121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are the mappings (hostname/username) done for a single subnet or just a group of ip-addresses ? Depending on the ips you can use include/exclude list or ignore list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While using include exclude list you need mention the subnet's who mapping info you need and those you don't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If its random but same ips you can use the ignore list, which can configured the following way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2893"&gt;How to Ignore Users in User-ID Agent&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 14:50:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23475#M17121</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-10-07T14:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23476#M17122</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are talking about the same subnet as our domain: as described these laptops are in fact domain members. But on some we use local users.&lt;/P&gt;&lt;P&gt;So there is no way I can filter out certain IP's, because then I probably would not have user id for domain users who log on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other suggestion is not too good as well:&lt;/P&gt;&lt;P&gt;If I ignore user "administrator", it would also ignore my domain administrator. Idem for local users who are equal to domain users.&lt;/P&gt;&lt;P&gt;Using the netbios\username notation, it would be quite a hassle to administer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really wonder why the implementation is so very different with the new agent version in comparison with the old.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit:&lt;/P&gt;&lt;P&gt;In 3.1.2 in the config.xml you have a value like&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;domain&amp;gt;mydomain.local&amp;lt;/domain&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's no such value in 5.0.6-6 UserIDAgentConfig.xml. Or is it just not documented ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 15:02:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23476#M17122</guid>
      <dc:creator>dieter_b</dc:creator>
      <dc:date>2013-10-07T15:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID agent collecting non-domain user-ip mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23477#M17123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The hostname is unique to each device so you can use a ignore list, the administrator name may be the same but, the domain the user name is in are different.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 15:17:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-collecting-non-domain-user-ip-mappings/m-p/23477#M17123</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2013-10-07T15:17:41Z</dc:date>
    </item>
  </channel>
</rss>

