<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Palo Alto 2020 doesn't close session when using AD authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26671#M19481</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible that the second user doesn't logon to the domain? The agent monitors logins but is not aware of logouts, so if user "A" logins, then logs out, and then user "B" from the same workstation logs in locally, the agent will not see a new login for that same workstation and thus assume user "A" is still using that IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jun 2012 14:37:12 GMT</pubDate>
    <dc:creator>npare</dc:creator>
    <dc:date>2012-06-01T14:37:12Z</dc:date>
    <item>
      <title>Palo Alto 2020 doesn't close session when using AD authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26670#M19480</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might be a really easy thing I have missed but when we try to authenticate against our AD users instead of strictly by IP and zone it works fine the first person to log on. But then if you log off and someone else with less privilages logs on they get whatever access the previous person had, which could be a problem especially if the last person to log on was the domain admin for instance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions as to why this might be?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 09:28:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26670#M19480</guid>
      <dc:creator>slawek.kunach</dc:creator>
      <dc:date>2012-06-01T09:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 2020 doesn't close session when using AD authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26671#M19481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible that the second user doesn't logon to the domain? The agent monitors logins but is not aware of logouts, so if user "A" logins, then logs out, and then user "B" from the same workstation logs in locally, the agent will not see a new login for that same workstation and thus assume user "A" is still using that IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 14:37:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26671#M19481</guid>
      <dc:creator>npare</dc:creator>
      <dc:date>2012-06-01T14:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 2020 doesn't close session when using AD authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26672#M19482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, they are definatly both domain users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One thing that might help. I have 2 DC's in my forest. Perhaps my Palo Alto box only picks up logons that have authenticated with DC1?&lt;/P&gt;&lt;P&gt;But the only way I could have seen that happening if it was a one off as DC2 is just there as a fail over in case DC1 becomes unavailable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 15:46:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26672#M19482</guid>
      <dc:creator>slawek.kunach</dc:creator>
      <dc:date>2012-06-01T15:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 2020 doesn't close session when using AD authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26673#M19483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please check the userID agent and confirm that it's monitoring both DC's.&amp;nbsp; Also, check the agent's log to ensure that the agent has the permission to read the security log of both DC's.&amp;nbsp; As long as the 2nd user logs into the AD domain, the agent will detect the 2nd user and update the PA device.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 16:17:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26673#M19483</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-06-01T16:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 2020 doesn't close session when using AD authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26674#M19484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What are the default settings regarding TTL's for the user-cache in the pan-agent?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And how will enabling WMI improve the hitrate?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 18:30:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26674#M19484</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-06-01T18:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 2020 doesn't close session when using AD authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26675#M19485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have checked and yes the 2nd DC is set in the Palo Alto and yes they have permissions to read the security logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also the default User TTL is 60 min under User idenfication in the ID agent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 14:00:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26675#M19485</guid>
      <dc:creator>slawek.kunach</dc:creator>
      <dc:date>2012-06-12T14:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Palo Alto 2020 doesn't close session when using AD authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26676#M19486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would recommend opening a case with Support.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 14:33:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/palo-alto-2020-doesn-t-close-session-when-using-ad/m-p/26676#M19486</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2012-06-12T14:33:55Z</dc:date>
    </item>
  </channel>
</rss>

