<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identified User and NAT in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34786#M25534</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kdd,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User names or User groups are defined in the security policy.&lt;/P&gt;&lt;P&gt;In the Nat rules the options available are source IPs and source zone and destination zone to indicate Nat rules. Later select source Nat or destination Nat.&lt;/P&gt;&lt;P&gt;Nat need not have the Usernames because all this is controlled from the security rules ie user and custom application ( firefox browser here )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Docs would help:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3469"&gt;Security Policy Guidelines&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jan 2014 14:37:06 GMT</pubDate>
    <dc:creator>Phoenix</dc:creator>
    <dc:date>2014-01-23T14:37:06Z</dc:date>
    <item>
      <title>Identified User and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34782#M25530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for certain of our users is it aloud to use firefox. they are identified by their username. But if the want to go to internet they have to be "NATted" . It is possible and when how to create a NAT-Rule? What is known:&amp;nbsp; username and the application.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="NAT-question.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11295_NAT-question.PNG.png" style="width: 620px; height: 36px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 13:04:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34782#M25530</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-01-23T13:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identified User and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34783#M25531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you could create a nat rule base on group or username and base on an custom application&lt;/P&gt;&lt;P&gt;custom application with signature base on the user-agent header that contain firefox.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 13:45:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34783#M25531</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-23T13:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identified User and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34784#M25532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2015"&gt;Custom Application Signatures&lt;/A&gt;&lt;/P&gt;&lt;P&gt;to create your custom app&lt;/P&gt;&lt;P&gt;and to identify user you need user id&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6172"&gt;Installation and Provisioning of the User Agent&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1052"&gt;User-ID Agent Setup Tips&lt;/A&gt;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 14:00:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34784#M25532</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-23T14:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identified User and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34785#M25533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we use PAN-OS 5.0.5 and in NAT-Rules there is no column for users.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Nat.PNG.png" class="jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/11296_Nat.PNG.png" style="width: 620px; height: 9px;" /&gt;&lt;/P&gt;&lt;P&gt;the custom application still exists.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 14:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34785#M25533</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-01-23T14:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identified User and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34786#M25534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Kdd,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User names or User groups are defined in the security policy.&lt;/P&gt;&lt;P&gt;In the Nat rules the options available are source IPs and source zone and destination zone to indicate Nat rules. Later select source Nat or destination Nat.&lt;/P&gt;&lt;P&gt;Nat need not have the Usernames because all this is controlled from the security rules ie user and custom application ( firefox browser here )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Docs would help:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1517"&gt;Understanding PAN-OS NAT&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-3469"&gt;Security Policy Guidelines&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 14:37:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34786#M25534</guid>
      <dc:creator>Phoenix</dc:creator>
      <dc:date>2014-01-23T14:37:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identified User and NAT</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34787#M25535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes I agree &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 14:41:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/identified-user-and-nat/m-p/34787#M25535</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-23T14:41:07Z</dc:date>
    </item>
  </channel>
</rss>

