<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: machine authentication in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31484#M23033</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so basically, just use the userid agent as usual...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when creating a security policy, under source user, append the $ sign at the end (ie mydomain\computername$)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but what if we do not want to list every single computer, just filter the domain? as far as i know, there is no wildcard for this, you can not enter mydomain\*$&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Apr 2014 12:47:40 GMT</pubDate>
    <dc:creator>bsimunko@recro-net.hr</dc:creator>
    <dc:date>2014-04-22T12:47:40Z</dc:date>
    <item>
      <title>machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31482#M23031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a need to identify user machines associated with a domain. specifically, we want to create security policies based upon domain membership. is that even possible, and how would we achieve this functionality?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thnx!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 12:21:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31482#M23031</guid>
      <dc:creator>bsimunko@recro-net.hr</dc:creator>
      <dc:date>2014-04-22T12:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31483#M23032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best to start here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6591"&gt;User-ID Best Practices - PAN-OS 5.0, 6.0&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 12:27:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31483#M23032</guid>
      <dc:creator>Rham</dc:creator>
      <dc:date>2014-04-22T12:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31484#M23033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so basically, just use the userid agent as usual...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when creating a security policy, under source user, append the $ sign at the end (ie mydomain\computername$)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but what if we do not want to list every single computer, just filter the domain? as far as i know, there is no wildcard for this, you can not enter mydomain\*$&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 12:47:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31484#M23033</guid>
      <dc:creator>bsimunko@recro-net.hr</dc:creator>
      <dc:date>2014-04-22T12:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31485#M23034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;crete&lt;/SPAN&gt; a user group in your AD server, which will include all domain users and map under Device &amp;gt;&amp;gt; User Identification &amp;gt;&amp;gt; Group-mapping. After that, you can refer that group under security policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 15:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31485#M23034</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-04-22T15:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31486#M23035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i feel like the message is not really going through...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am not asking about identification of users (humans), i'm asking about identifying computers (machines) that are domain members. i would like to have a set of policies applied for all COMPUTERS that are members and a different set for non-domain COMPUTERS (for example guests on the network)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 15:48:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31486#M23035</guid>
      <dc:creator>bsimunko@recro-net.hr</dc:creator>
      <dc:date>2014-04-22T15:48:53Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31487#M23036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you trying to map IPs to both users and computers, so that if it is the computer making the request, it shows up as the computer account instead of the user that was last logged in/cached on that IP? Just trying to help clarify, so I don't actually have an answer for the question, but this is what I understood from your original question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 15:58:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31487#M23036</guid>
      <dc:creator>hheck</dc:creator>
      <dc:date>2014-04-22T15:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31488#M23037</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, that is what i'm trying to do! i am not interested in the logged in user, just the computer (and they are NOT terminals).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i know it sounds silly, but customers are silly sometimes....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 16:02:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31488#M23037</guid>
      <dc:creator>bsimunko@recro-net.hr</dc:creator>
      <dc:date>2014-04-22T16:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31489#M23038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;one way to identify if pc is domain or non-domain is to make use of the HIP profiles and use the hip profile in the security policy. To get the HIP report, you will have to configure gloabal protect for internal gateway . You will need Global protect portal license for internal gateways &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="3930" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-3930"&gt;https://live.paloaltonetworks.com/docs/DOC-3930&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; - How to Configure Internal GlobalProtect Only &lt;/SPAN&gt;&lt;A class="jive-link-wiki-small" data-containerid="2027" data-containertype="14" data-objectid="6066" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-6066"&gt;https://live.paloaltonetworks.com/docs/DOC-6066&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; - configuring HIP profiles to use in security policies&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 17:14:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31489#M23038</guid>
      <dc:creator>knarra1</dc:creator>
      <dc:date>2014-04-22T17:14:25Z</dc:date>
    </item>
    <item>
      <title>Re: machine authentication</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31490#M23039</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HIP has nothing to do with the request. What he is looking to do is to differentiate traffic that is initiated by the SYSTEM account, and other non user accounts, versus what is initiated by the user accounts. This way he can have a policy that says "group of computer" can access APP, but the user initiated traffic doesn't necessarily have to be allowed to do that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's one thing to associate a user to an IP, which is what is currently done. What he is looking for is to associate TRAFFIC to a user.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Apr 2014 17:19:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/machine-authentication/m-p/31490#M23039</guid>
      <dc:creator>hheck</dc:creator>
      <dc:date>2014-04-22T17:19:51Z</dc:date>
    </item>
  </channel>
</rss>

