<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID - wrong user domain in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28826#M21051</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "wrong domain" issue seems to be gone as of now. At least we didn't see any log entry with the wrong domain so far. Thanks a lot for this hint. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, we're now facing another issue that seems to be related with this change. Suddenly for some connections the source user isn't detected at all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PanoramaLog.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8662_PanoramaLog.png" style="width: 620px; height: 472px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Sep 2013 13:54:46 GMT</pubDate>
    <dc:creator>oschuler</dc:creator>
    <dc:date>2013-09-30T13:54:46Z</dc:date>
    <item>
      <title>User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28822#M21047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We discovered an issue with our User-ID setup in our BranchOffices. Some times the source user is not recognized as &lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;lt;child-domain&amp;gt;\&amp;lt;user&amp;gt;&lt;/SPAN&gt; but as &lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;lt;parent-domain&amp;gt;\&amp;lt;user&amp;gt;&lt;/SPAN&gt;. This happens from time to time but only for a short perioid of time (less than 30 seconds).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="8647" alt="LogExcerpt.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8647_LogExcerpt.png" style="width: 620px; height: 127px;" /&gt;&lt;/P&gt;&lt;P&gt;Does anyone have an idea on how we could further troubleshoot this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's our setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BranchOffice:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- PA-200 (v5.0.7)&lt;/P&gt;&lt;P&gt;- Local Domain Controller (Win2012) --&amp;gt; &lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;lt;child-domain&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- Local PA-200 queries the security log of the local DC every 2 seconds, no WMI probing&lt;/P&gt;&lt;P&gt;- In addition two User-ID agents are configured. The two agents are hosted on servers in the HQ (see below).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Headquarters:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- PA-2050&lt;/P&gt;&lt;P&gt;- Four local Domain Controllers (Win2012) --&amp;gt; &lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;lt;parent-domain&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- One Backup Domain Controller (Win2012) --&amp;gt; &lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;lt;child-domain&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;- Two servers with User-ID Agents installed (not installed on DCs directly). The User-ID agents query only local DCs, meaning the four DCs of the parent domain plus the backup DC of the child-domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the local PA-200 has two sources to get user-ip mapping information from:&lt;/P&gt;&lt;P&gt;- The local DC&lt;/P&gt;&lt;P&gt;- The two User-ID agents in the HQ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;That user only exists in the child domain but it uses various services hosted in the parent domain (like MS Exchange). &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Any help is appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Sep 2013 12:40:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28822#M21047</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-09-27T12:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28823#M21048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you filter the sessions with different(wrong) domain do you see anyhting common with these sessions ?&lt;/P&gt;&lt;P&gt;How many Ldap profile do you have ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Sep 2013 20:22:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28823#M21048</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-09-27T20:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28824#M21049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The PA 200 you said scours the ,local DC logs and so I presume you have an Agentless UserID agent there. &lt;/P&gt;&lt;P&gt;Could you please check to see if this Agentless userID is set for "session read"&amp;nbsp; Device&amp;gt;&amp;gt;UserID&amp;gt;&amp;gt;User Mappinig&amp;gt;&amp;gt; Enable Session (is this checked)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, this means that when a user from the Child Domain uses one of the resources (like MS Exchange / file server), that user is logged and mapped. You stated that "&lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;That user only exists in the child domain but it uses various services hosted in the parent domain (like MS Exchange)&lt;/SPAN&gt;" At the time that the user goes to one of these resources he/she gets logged with the Parent Domain&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;If you'd like to NOT see the user with the Parent Domain, disable "Enable session" (Uncheck the box) so when a user does access those MS resources they are not mapped/logged&amp;nbsp; with the Parent domain&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Sep 2013 20:57:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28824#M21049</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2013-09-27T20:57:02Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28825#M21050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you both for your hints.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@panos&lt;/P&gt;&lt;P&gt;I prepared a log filter that shows me the entries with the wrong (parent) domain. I don't see any specific pattern so far. Most connections are logged to "External L3" zone but but there are also some that egress on the "Branch VPN L3" or "Branch MPLS L3" zones... Destination IPs and ports didin't reveal any pattern to me. But still a good hint for troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@sjamaluddin&lt;/P&gt;&lt;P&gt;You're right. The local PA-200 uses an agentless setup to query the local domain controller. You're also right that the "Enable Session" option &lt;STRONG&gt;is checked&lt;/STRONG&gt;. I just disabled that option. I'll re-check the firewall logs after tomorrow to see if the issue disappeared. I'll keep you posted. &lt;/P&gt;&lt;P&gt;Is it advised to disable that option in a multi-domain environment in general? Should we disable it on the UserID agents in HQ as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot!&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 29 Sep 2013 13:31:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28825#M21050</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-09-29T13:31:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28826#M21051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "wrong domain" issue seems to be gone as of now. At least we didn't see any log entry with the wrong domain so far. Thanks a lot for this hint. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, we're now facing another issue that seems to be related with this change. Suddenly for some connections the source user isn't detected at all:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PanoramaLog.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/8662_PanoramaLog.png" style="width: 620px; height: 472px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;P&gt;Oliver&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 13:54:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28826#M21051</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-09-30T13:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28827#M21052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone? I think we need to check this "Enable Session" again as people are already complaining &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 08:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28827#M21052</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-10-02T08:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28828#M21053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That should not be related to session read, because as I see from logs 2 logs with same source dest. ip and port, and 1 have user and other not.That seems strange to me.&lt;/P&gt;&lt;P&gt;I wonder if you can just use user-id agent and disable completely agentless system or not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 17:17:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28828#M21053</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2013-10-02T17:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28829#M21054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hmm, I guess we can try that. But we only have UserID agents installed on servers in the HQ. That would mean these two agents would have to query the remote DC in the branch office over WAN...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Oct 2013 19:36:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28829#M21054</guid>
      <dc:creator>oschuler</dc:creator>
      <dc:date>2013-10-02T19:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID - wrong user domain</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28830#M21055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If there are users that have disappeared completely since disabling Server Session, are you not logging those users through a regular AD log on event? Could you check whether or not there is a log on entry for those users in AD&lt;/P&gt;&lt;P&gt;If Server session is the only way you were logging those users then that may explain why those users have disappeared from your logs (and why they may not be falling in the correct security rules).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please ensure that the DC has these users' log on events and if not - then that would imply that you are only using server session to map these users in which case you may be forced to re-enable server session.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 07 Oct 2013 17:49:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wrong-user-domain/m-p/28830#M21055</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2013-10-07T17:49:54Z</dc:date>
    </item>
  </channel>
</rss>

