<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Implementing User Identification via AD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32434#M23769</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to implement user identification via active directory on PA-200. I've added the AD server under &lt;EM&gt;Device -&amp;gt; LDAP&lt;/EM&gt; and added group mapping under &lt;EM&gt;Device -&amp;gt; User Identification.&lt;/EM&gt;Now I guess I need to install user-ID agent on a local machine but I can't find a download link for this app. &lt;/P&gt;&lt;P&gt;Is it possible to implement user identification without this user-id agent?&lt;/P&gt;&lt;P&gt;Can anyone provide a simple guide for this whole process? I'm using few documents but wasn't able to find a single document that explains this procedure from start to end on a simple example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Damir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2012 08:18:18 GMT</pubDate>
    <dc:creator>damir_porobic</dc:creator>
    <dc:date>2012-07-18T08:18:18Z</dc:date>
    <item>
      <title>Implementing User Identification via AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32434#M23769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to implement user identification via active directory on PA-200. I've added the AD server under &lt;EM&gt;Device -&amp;gt; LDAP&lt;/EM&gt; and added group mapping under &lt;EM&gt;Device -&amp;gt; User Identification.&lt;/EM&gt;Now I guess I need to install user-ID agent on a local machine but I can't find a download link for this app. &lt;/P&gt;&lt;P&gt;Is it possible to implement user identification without this user-id agent?&lt;/P&gt;&lt;P&gt;Can anyone provide a simple guide for this whole process? I'm using few documents but wasn't able to find a single document that explains this procedure from start to end on a simple example.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Damir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 08:18:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32434#M23769</guid>
      <dc:creator>damir_porobic</dc:creator>
      <dc:date>2012-07-18T08:18:18Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing User Identification via AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32435#M23770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Hi Damir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not much help, as I'm trying to figure this out too.&amp;nbsp; But I did find the User ID Agent software here;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=nu_sw_updates&amp;amp;Itemid=164" title="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=nu_sw_updates&amp;amp;Itemid=164"&gt;Palo Alto Networks&amp;lt;/title&amp;gt; &amp;lt;meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /&amp;gt; &amp;lt;meta http-equiv="X-UA-Compatible" content="IE=edge"&amp;gt;&amp;lt;title&amp;gt;Palo Alto Networks&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 09:48:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32435#M23770</guid>
      <dc:creator>BlackfenSchool</dc:creator>
      <dc:date>2012-07-18T09:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing User Identification via AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32436#M23771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Damir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need&amp;nbsp; the agent to get ip to user mapping. You can download the agent from the support portal:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=nu_sw_updates&amp;amp;Itemid=164" title="https://support.paloaltonetworks.com/index.php?option=com_pan&amp;amp;task=nu_sw_updates&amp;amp;Itemid=164"&gt;Palo Alto Networks&amp;lt;/title&amp;gt; &amp;lt;meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /&amp;gt; &amp;lt;meta http-equiv="X-UA-Compatible" content="IE=edge"&amp;gt;&amp;lt;title&amp;gt;Palo Alto Networks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This document walks you through the installation procedure for the PANOS 4.1. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-2132"&gt;https://live.paloaltonetworks.com/docs/DOC-2132&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 17:25:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32436#M23771</guid>
      <dc:creator>zarina</dc:creator>
      <dc:date>2012-07-18T17:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing User Identification via AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32437#M23772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't forget to enable user identification on your trusted zone.&amp;nbsp; I missed that tick box, and spent over an hour trying to figure out why it wasn't working.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 17:54:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32437#M23772</guid>
      <dc:creator>BlackfenSchool</dc:creator>
      <dc:date>2012-07-18T17:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing User Identification via AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32438#M23773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Shaun, I'll try it with this guide, it's actually what I was looking for... &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 18:10:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32438#M23773</guid>
      <dc:creator>damir_porobic</dc:creator>
      <dc:date>2012-07-18T18:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing User Identification via AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32439#M23774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, this was the first step, now I need to configure the User-ID Agent and PA Firewall.&lt;/P&gt;&lt;P&gt;I have configured an User-id agent under &lt;EM&gt;Device -&amp;gt; User Identification -&amp;gt; User-ID Agents&lt;/EM&gt; but its Connected Status is Red. And yes, I have enabled user identification on the trusted zone.&lt;/P&gt;&lt;P&gt;Another interesting thing is that I can't see any logs on the User-ID Agent. I see all users that are active one the network under the &lt;EM&gt;Monitoring&lt;/EM&gt; option but no logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Solution:&lt;/P&gt;&lt;P&gt;It looks like I forgot to add the PA-200 to the list of allowed devices to access the User-ID agent. Now it works fine as far as I can see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Damir&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Message was edited by: Damir Porobic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 07:17:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32439#M23774</guid>
      <dc:creator>damir_porobic</dc:creator>
      <dc:date>2012-07-19T07:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Implementing User Identification via AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32440#M23775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THIS ^. I did not know that checkbox was there under the zone config. Would have been here all day...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Apr 2013 15:33:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/implementing-user-identification-via-ad/m-p/32440#M23775</guid>
      <dc:creator>kwj</dc:creator>
      <dc:date>2013-04-19T15:33:27Z</dc:date>
    </item>
  </channel>
</rss>

