<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security policies did not take effect after Sleep Mode in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32469#M23795</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One good test to to check whether the PA loses the Ip-user mapping up on switching the laptop to sleep mode ( which is the reason why the user does not hit the policy created for him), we could check the ip-user mapping table on the PA using the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;show user ip-user-mapping all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will give us a better indication of how to avoid that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would understand why a log off and log on would reinstate the mapping considering the fact the PA will look at the event logs of the DC to track LOG ON success events to enumerate user to ip mapping&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Jul 2013 16:51:43 GMT</pubDate>
    <dc:creator>Chatri</dc:creator>
    <dc:date>2013-07-03T16:51:43Z</dc:date>
    <item>
      <title>Security policies did not take effect after Sleep Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32468#M23794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just like to find out if there is a known&amp;nbsp; issue with Palo Alto and Windows 8 for direct internet policy.&amp;nbsp; Currently, we have defined a policy in PA to allow AD user to connect to internet.&amp;nbsp; However, based on my observation, once my notebook goes to sleep mode, then wake up, then login the policy doesn’t seem to take effect.&amp;nbsp; To gain direct internet access what I need to do is to log off then log in again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Xer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 16:35:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32468#M23794</guid>
      <dc:creator>mbs.admin</dc:creator>
      <dc:date>2013-07-03T16:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies did not take effect after Sleep Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32469#M23795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One good test to to check whether the PA loses the Ip-user mapping up on switching the laptop to sleep mode ( which is the reason why the user does not hit the policy created for him), we could check the ip-user mapping table on the PA using the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;show user ip-user-mapping all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will give us a better indication of how to avoid that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would understand why a log off and log on would reinstate the mapping considering the fact the PA will look at the event logs of the DC to track LOG ON success events to enumerate user to ip mapping&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 16:51:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32469#M23795</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-07-03T16:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies did not take effect after Sleep Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32470#M23796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chatri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm just wondering why PA lost the ip-user-mapping considering that the user didn't logged off? Isn't it a bug in PA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 17:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32470#M23796</guid>
      <dc:creator>mbs.admin</dc:creator>
      <dc:date>2013-07-03T17:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies did not take effect after Sleep Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32471#M23797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Xer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Palo Alto will will not know if the device is in sleep mode or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Palo Alto will only look at four event Ids in the security logs of the domain controller to get the mappings ( all four event IDs correspond to log on events, the PA does not see the Log off events).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But yes, having said that when the PC is turned on from the sleep mode the DC should record an event of the user getting logged on and the PA should get the mapping back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It wont be a bad idea to open up a TAC case to see what exactly is causing the mapping to be lost.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope that is helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Jul 2013 17:21:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32471#M23797</guid>
      <dc:creator>Chatri</dc:creator>
      <dc:date>2013-07-03T17:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Security policies did not take effect after Sleep Mode</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32472#M23798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chatri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the support. But, after further investigation we think the problem is the communication of PANAgent to Palo Alto Firewall. The connection is intermittent and if we issue a ping command, the connection is stable. I attached the screenshot I got from the system log. every 2 to 10 minutes the agent gets disconnected. Have you encountered this before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="PANAgent.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/7214_PANAgent.jpg" width="450" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Jul 2013 04:27:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/security-policies-did-not-take-effect-after-sleep-mode/m-p/32472#M23798</guid>
      <dc:creator>mbs.admin</dc:creator>
      <dc:date>2013-07-08T04:27:49Z</dc:date>
    </item>
  </channel>
</rss>

