<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DHCP - Getting info on allocated IPs in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-getting-info-on-allocated-ips/m-p/2509#M1868</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have our PA-500 setup on our company's public network.&amp;nbsp; This network is used by employee's personal machines and clients machines when they come into our office.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have run into a few situations that we can see someone is most likely infected as the machine has been profiled by the PA-500 as transmitting threat traffic.&amp;nbsp; The problem is we only have an IP address of the machine that is doing the talking. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wondering if there is a way to get things like hostname, OS and version or any other easily identifiable information to find the infected machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Feb 2013 18:46:51 GMT</pubDate>
    <dc:creator>smithp</dc:creator>
    <dc:date>2013-02-04T18:46:51Z</dc:date>
    <item>
      <title>DHCP - Getting info on allocated IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-getting-info-on-allocated-ips/m-p/2509#M1868</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have our PA-500 setup on our company's public network.&amp;nbsp; This network is used by employee's personal machines and clients machines when they come into our office.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have run into a few situations that we can see someone is most likely infected as the machine has been profiled by the PA-500 as transmitting threat traffic.&amp;nbsp; The problem is we only have an IP address of the machine that is doing the talking. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wondering if there is a way to get things like hostname, OS and version or any other easily identifiable information to find the infected machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 18:46:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-getting-info-on-allocated-ips/m-p/2509#M1868</guid>
      <dc:creator>smithp</dc:creator>
      <dc:date>2013-02-04T18:46:51Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP - Getting info on allocated IPs</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-getting-info-on-allocated-ips/m-p/2510#M1869</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;SInce you are handing out IP addresses via DHCP, you will have the Mac address of the machine that is having this IP address. Apart from the MAC address PA-500 does not have any information like OS or any other information. If you have global protect in your network then PA-500 will have the information like hostname,OS, wether the machine has any antivirus software and so much other information.&amp;nbsp; At DHCP level I can only think of MAC address. You can always allocate same IP to that machine based on MAC address and you can block this IP traffic. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 19:39:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-getting-info-on-allocated-ips/m-p/2510#M1869</guid>
      <dc:creator>sdurga</dc:creator>
      <dc:date>2013-02-04T19:39:10Z</dc:date>
    </item>
  </channel>
</rss>

