<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Terminal Services User-ID Agent Flaw in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31003#M22689</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I have done so. Personally, I can work around it, and hopefully the custoemr can as well. I was just kind of surprised is all.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Nov 2011 21:26:34 GMT</pubDate>
    <dc:creator>dpayne</dc:creator>
    <dc:date>2011-11-23T21:26:34Z</dc:date>
    <item>
      <title>Terminal Services User-ID Agent Flaw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/30999#M22685</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A new customer during deployment was wanting to test how well the TS User ID agent was working at identifying users. We logged on as User A and started a specific ping. We search the log file, and there was the ping. We had it running continuous for several minutes. During a refresh, we started to notice that other users were also pinging this exact same address from the same TS. This was very unlikley, so we logged in User B. As soon as we logged in, the log indicated the User B was responsible for the pings, even though we could clearly see this was not the case. After explaining these results to Support, here was the explanation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since the TS User-ID agent uses port ranges to identify each user, it only is capable of identifying the traffic for a user if the protocol tcp/udp (because they are port based).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer is a Bank, and they consider the feature unusable, because&amp;nbsp; the last user to login, may not be allowed to ping, or gre, or whatever.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone else noticed this behavior? Any workarounds or fixes in the mix?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 18:37:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/30999#M22685</guid>
      <dc:creator>dpayne</dc:creator>
      <dc:date>2011-11-23T18:37:59Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services User-ID Agent Flaw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31000#M22686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure why they would consider it "unusable?"&amp;nbsp; The main purpose of the TS UserID function is to enable you to do per-user web filtering from a Terminal Server, without having to use virtual IPs per each individual.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would never allow my users to do anything that would involve GRE from a terminal server.&amp;nbsp; That could do $deity knows what to other people on the same terminal server and is not a good idea.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ping is ICMP so it isn't tracked by UserID, but really, is that something you are concerned about?&amp;nbsp; Our users can't even access the command line on our terminal servers, so they don't really have any way to ping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 19:08:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31000#M22686</guid>
      <dc:creator>bradenmcg</dc:creator>
      <dc:date>2011-11-23T19:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services User-ID Agent Flaw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31001#M22687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I suppose that's fine if you only want web filtering, however, that is not the case here. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 20:04:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31001#M22687</guid>
      <dc:creator>dpayne</dc:creator>
      <dc:date>2011-11-23T20:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services User-ID Agent Flaw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31002#M22688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@dpayne:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you have learned from your call to Technical Support the Terminal Services agent works by restricting the source port on a per user basis for TCP and UDP protocols. For applications that use other network protocols the Terminal Services agent will be unable to perform any function.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wish to see the Terminal Services agent support protocols other than TCP and UDP you will need to have your sales team submit a feature request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Benjamin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 21:21:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31002#M22688</guid>
      <dc:creator>bpappas</dc:creator>
      <dc:date>2011-11-23T21:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal Services User-ID Agent Flaw</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31003#M22689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I have done so. Personally, I can work around it, and hopefully the custoemr can as well. I was just kind of surprised is all.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Nov 2011 21:26:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-services-user-id-agent-flaw/m-p/31003#M22689</guid>
      <dc:creator>dpayne</dc:creator>
      <dc:date>2011-11-23T21:26:34Z</dc:date>
    </item>
  </channel>
</rss>

