<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting User-ID when using 802.1x Wireless in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/getting-user-id-when-using-802-1x-wireless/m-p/26963#M19700</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if any of you chaps and/or chapesses have come across a problem getting the correct User-ID information when using wireless authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I have is that I have a Palo Alto firewall that happily uses the User-ID Agent from AD/Security Event log to get User-ID information about wired connections to their network.&amp;nbsp; The customer also has an Aruba wireless network using 802.1x authentication via an NPS service backed off to their Windows AD.&amp;nbsp; Because the authentication request appears to come from the Aruba Wireless Switch, via an NPS server on the network, the information recorded in the Security event log has the relevant user with the IP address of the wireless switch.&amp;nbsp; The client device hasn't been granted any wireless network rights until it is authenticated, not even access to the DHCP server, and therefore doesn't have a IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once the client is authenticated, it is issued an IP address, which doesn't match the one in the event log and therefore the Palo Alot doesn't tie this IP address to this user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance on this would be grateful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 20 Sep 2013 11:52:46 GMT</pubDate>
    <dc:creator>PaulBarrington</dc:creator>
    <dc:date>2013-09-20T11:52:46Z</dc:date>
    <item>
      <title>Getting User-ID when using 802.1x Wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-user-id-when-using-802-1x-wireless/m-p/26963#M19700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if any of you chaps and/or chapesses have come across a problem getting the correct User-ID information when using wireless authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem I have is that I have a Palo Alto firewall that happily uses the User-ID Agent from AD/Security Event log to get User-ID information about wired connections to their network.&amp;nbsp; The customer also has an Aruba wireless network using 802.1x authentication via an NPS service backed off to their Windows AD.&amp;nbsp; Because the authentication request appears to come from the Aruba Wireless Switch, via an NPS server on the network, the information recorded in the Security event log has the relevant user with the IP address of the wireless switch.&amp;nbsp; The client device hasn't been granted any wireless network rights until it is authenticated, not even access to the DHCP server, and therefore doesn't have a IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once the client is authenticated, it is issued an IP address, which doesn't match the one in the event log and therefore the Palo Alot doesn't tie this IP address to this user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance on this would be grateful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 11:52:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-user-id-when-using-802-1x-wireless/m-p/26963#M19700</guid>
      <dc:creator>PaulBarrington</dc:creator>
      <dc:date>2013-09-20T11:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Getting User-ID when using 802.1x Wireless</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-user-id-when-using-802-1x-wireless/m-p/26964#M19701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000;"&gt;Following solutions would be helpful in this scenario :&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000;"&gt;1&amp;gt; &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4730"&gt;Scripting solution for User ID working with Microsoft IAS/NPS&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000;"&gt;2&amp;gt; &lt;SPAN style="line-height: 1.5em;"&gt;The following Doc talks about &lt;/SPAN&gt;&lt;SPAN style="font-size: 12.222222328186035px; line-height: 1.5em; font-style: inherit; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;Radius &lt;/SPAN&gt;&lt;SPAN style="line-height: 1.5em;"&gt;and User-ID integration in the environments using 802.1x devices and wireless access points and controllers.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;A script can be &lt;/SPAN&gt;configured to run on the Syslog server that will extract the user and IP information from the message, format it correctly for the UID-API, and then send it to the API agent.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000;"&gt;&lt;A _jive_internal="true" data-containerid="2010" data-containertype="14" data-objectid="1936" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1936" style="font-style: inherit; font-family: inherit; color: #006595;"&gt;UserID API integration using Syslog&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000;"&gt; &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; font-size: 10pt; line-height: 1.5em;"&gt;Also check :&lt;/SPAN&gt;&lt;A _jive_internal="true" data-containerid="2004" data-containertype="14" data-objectid="7239" data-objecttype="1" href="https://live.paloaltonetworks.com/thread/7239" style="font-family: inherit; font-size: 10pt; line-height: 1.5em; font-style: inherit; color: #006595;"&gt;https://live.paloaltonetworks.com/thread/7239&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Sep 2013 12:32:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-user-id-when-using-802-1x-wireless/m-p/26964#M19701</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-09-20T12:32:03Z</dc:date>
    </item>
  </channel>
</rss>

