<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Devices (Apple &amp; Android) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25324#M18453</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Benjamin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I take it that only unknow user accounts will get the prompt?&amp;nbsp; What happens when we have vistors who wouldnt have an account in the domain?&amp;nbsp; We do not have or use anytype of guest account.&amp;nbsp; We do sometimes allow a device like a laptop to connect through our network to the internet and use the Default profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 01 Jun 2011 15:50:06 GMT</pubDate>
    <dc:creator>fnichelson</dc:creator>
    <dc:date>2011-06-01T15:50:06Z</dc:date>
    <item>
      <title>Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25316#M18445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;Our school district has started purchasing mobile devices, the iPad2's and some Xooms.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;I've noticed in the Monitor logs that they don’t always fall until the default rule?&amp;nbsp; So far two have been using the Admin rule which opens all but Adult content.&amp;nbsp; These devices are not logging into the domain, they do not requester with DNS but they do get their IP's from DHCP.&amp;nbsp; My life would be great if there was an App for that but so far, none.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;Can you tell me if there anyone is currently working of creating one or tell me what are the best ways to ensure these devices do not get access to any rule other than the default rule unless its one of Supers who are getting them, I do need to see how best to get them into their own rule also.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;Anyone, I need help!&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin:0in;margin-bottom:.0001pt;background:#F8FAFD"&gt;&lt;SPAN style="font-size:10.0pt;font-family:&amp;amp;quot;Arial&amp;amp;quot;,&amp;amp;quot;sans-serif&amp;amp;quot;;color:#333333"&gt;Thanks for any replies.&lt;SPAN style="mso-spacerun:yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 14:18:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25316#M18445</guid>
      <dc:creator>fnichelson</dc:creator>
      <dc:date>2011-06-01T14:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25317#M18446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;FN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I didn't know better, I would say that the tablet users are sometimes picking up a DHCP address that was recently in use by a domain user which has not yet timed out the user-to-ip-mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your situation may require a re-examination of the timer settings for your Pan Agent to reduce the chances that a non-domain member device will gain access to the network and be incorrectly identified.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example: &lt;/P&gt;&lt;P&gt;If your Pan Agent "Age-out Timeout" is set to 10 hours&lt;/P&gt;&lt;P&gt;User "Principal" logs in @ 9am and actively uses his computer until noon. @ Noon Principal goes offsite to a meeting and takes his laptop with him. @ this point in time the Age-out Timeout for Principal's user-to-ip-mapping has a minimum of 7 hours remaining (possibly longer if the user had performed any activities that renewed the timer value). &lt;/P&gt;&lt;P&gt;@ 1PM a tablet user requests a DHCP address and happens to get the IP that was being used by Principal during the morning. @ this point the Pan Device will still see this IP as mapped to "Principal" and apply policies accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some environments do benefit from using Netbios or WMI probing to reduce the chances that the example scenario above will occur, but this will require that all domain member computers allow Netbios or WMI probing because a failed probe event will result in the IP being marked as _unknown_ and security policies will be applied based upon this identification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 14:32:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25317#M18446</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-06-01T14:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25318#M18447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What would be the impact on the PA Devices and the AD servers the agent queries should the timer be set to a lower value?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:12:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25318#M18447</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-06-01T15:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25319#M18448</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That most helpful and I am looking into it.&amp;nbsp; But some of these devices are going to used by staff who like myself have our own URL Filtering Profiles which allows greater internet access.&amp;nbsp; Is there a way that Palo can see these devices for what they are and assign them to the correct URL Filtering Profile?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We locked down who has access to our access points so anyone with one of these devices will fall within a group with more internet access like our District Superintendent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:23:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25319#M18448</guid>
      <dc:creator>fnichelson</dc:creator>
      <dc:date>2011-06-01T15:23:49Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25320#M18449</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@MT: The firewall queries the PAN Agent(s) for updates every two seconds and when an unknown IP from a security zone with user identification enabled attempts to pass traffic through the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enabling Netbios/WMI probing will increase the amount of traffic between the Pan Agent server and the subnets that it is configured to track for user-to-ip-mapping. The amount of traffic will be based upon the number of users who logon each day and the Netbios/WMI probe timer value.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:26:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25320#M18449</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-06-01T15:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25321#M18450</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@FN: if a device is not going to logon to the domain (smartphone, tablet, etc) then I would advise using the Captive Portal feature of the PAN device to identify unknown users and create a user-to-ip-mapping for their device(s).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Documentation for Captive Portal setup can be found here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1630"&gt;https://live.paloaltonetworks.com/docs/DOC-1630&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:29:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25321#M18450</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-06-01T15:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25322#M18451</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At this time we know of no way for these devices to log into the domain (No app for that) I will take a look at this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I take it that the Palo device can not see these devices for what they are in the ACC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:35:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25322#M18451</guid>
      <dc:creator>fnichelson</dc:creator>
      <dc:date>2011-06-01T15:35:55Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25323#M18452</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@FN: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive Portal will prompt the users of these devices to provide logon information in a web browser SSL session. Any smartphone or tablet will be able to perform this task.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If a user is not identified then the ACC reporting will only show the IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:45:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25323#M18452</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-06-01T15:45:40Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25324#M18453</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Benjamin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I take it that only unknow user accounts will get the prompt?&amp;nbsp; What happens when we have vistors who wouldnt have an account in the domain?&amp;nbsp; We do not have or use anytype of guest account.&amp;nbsp; We do sometimes allow a device like a laptop to connect through our network to the internet and use the Default profile.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:50:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25324#M18453</guid>
      <dc:creator>fnichelson</dc:creator>
      <dc:date>2011-06-01T15:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Devices (Apple &amp; Android)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25325#M18454</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@FN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;unknown IP addresses will get the Captive Portal page.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;login authentication is done via local DB, RADIUS, LDAP or Kerberos (Kerb only an option on PANOS 4.0 and higher).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for users who are guests you would need to have a guest account available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2011 15:56:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mobile-devices-apple-android/m-p/25325#M18454</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-06-01T15:56:01Z</dc:date>
    </item>
  </channel>
</rss>

