<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID Agent odd outbound traffic patterns in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26100#M19051</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've noticed some strange traffic patterns coming from our Agent boxes and am curious why, and if others are seeing something similar... ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking in our Monitoring logs I see our two Agents sending data to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;14.1.1.19&lt;/P&gt;&lt;P&gt;14.2.1.19&lt;/P&gt;&lt;P&gt;14.2.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Via SMB ports 135,137,139&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This appears to be something out of Australia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're blocking this communication, and they're fresh boxes with Anti-Virus installed so it's really odd that we're seeing this..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 May 2012 17:19:30 GMT</pubDate>
    <dc:creator>steveo</dc:creator>
    <dc:date>2012-05-09T17:19:30Z</dc:date>
    <item>
      <title>User-ID Agent odd outbound traffic patterns</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26100#M19051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've noticed some strange traffic patterns coming from our Agent boxes and am curious why, and if others are seeing something similar... ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking in our Monitoring logs I see our two Agents sending data to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;14.1.1.19&lt;/P&gt;&lt;P&gt;14.2.1.19&lt;/P&gt;&lt;P&gt;14.2.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Via SMB ports 135,137,139&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This appears to be something out of Australia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're blocking this communication, and they're fresh boxes with Anti-Virus installed so it's really odd that we're seeing this..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 17:19:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26100#M19051</guid>
      <dc:creator>steveo</dc:creator>
      <dc:date>2012-05-09T17:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent odd outbound traffic patterns</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26101#M19052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is your settings your of userid agents?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think its recommended to disable netbios lookups but enable wmi lookups (if possible).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also in the menu enable debug log level and then watch the userid directory in program files and then copy the debug file as soon as you see this traffic (dont forget to change log level back to informational or such after you copied the debug log to not run out of disk).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully you can then find in the debuglog from where these ip addresses is pickedup (is it someone logging in to your exchange server or is it something else).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 May 2012 21:49:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26101#M19052</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-09T21:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent odd outbound traffic patterns</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26102#M19053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; UserAgents have a feature that scans workstations via WMI/Netbios. If you firewall request informations about an IP to a UserAgent (even if that IP is on internet), it will scan it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; If you don't want internet addresses to be scanned or IDed, look at your zone User Identification configuration and UserID doc in general.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2012 08:37:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26102#M19053</guid>
      <dc:creator>essnet</dc:creator>
      <dc:date>2012-05-10T08:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent odd outbound traffic patterns</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26103#M19054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We did have our Agents set to use Netbios so I disabled it, and now it seems to have quited down.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as zone ID goes we're only checking for IDs on our Trusted segment, IE: Trusted (Inside) -&amp;gt; Untrusted (Outside) -&amp;gt; Internet and not the reverse..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's strange that those couple hosts would keep coming up... Hmmm..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 17:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26103#M19054</guid>
      <dc:creator>steveo</dc:creator>
      <dc:date>2012-05-11T17:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID Agent odd outbound traffic patterns</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26104#M19055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If im not mistaken you can in the userid agent also filter which ip addresses it should lookup/handle.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2012 19:02:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-odd-outbound-traffic-patterns/m-p/26104#M19055</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-05-11T19:02:01Z</dc:date>
    </item>
  </channel>
</rss>

