<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't select users in policy in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40304#M29578</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Sascha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can replicate the same but i believe/confirmed that you can manually type the local users/groups in the policy and it works fine. One important thing to note is you can use these local user db only for ssl vpn users and captive port users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Subijith Raghunandan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Dec 2012 17:58:01 GMT</pubDate>
    <dc:creator>sraghunandan</dc:creator>
    <dc:date>2012-12-24T17:58:01Z</dc:date>
    <item>
      <title>Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40303#M29577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am playing with my little PA-200 and wanted to try user based policies. I added a couple of users to the local user database and grouped them into user groups. Now when I create a new policy (or modify an existing one), the source-user field stays empty, my users don't show up so I can't add them. Even when I start typing (for autocomplete) I don't get any results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Captive Portal, auth profile etc. are all configured as per documentation, and the interface is configured for UserID.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I missing here? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 16:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40303#M29577</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-12-24T16:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40304#M29578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Sascha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can replicate the same but i believe/confirmed that you can manually type the local users/groups in the policy and it works fine. One important thing to note is you can use these local user db only for ssl vpn users and captive port users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Subijith Raghunandan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 17:58:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40304#M29578</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-12-24T17:58:01Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40305#M29579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks. But I can't confirm this. I type in the full user/group name but it still doesn't work (I am using captive portal for this). By the way, this is PanOS 5.0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 18:36:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40305#M29579</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-12-24T18:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40306#M29580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sascha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try with users only and the authentication profile for CP has local db selected right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Subijith Raghunandan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 18:41:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40306#M29580</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-12-24T18:41:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40307#M29581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It has local DB selected. I tried with users only, but to no avail. If enabled with a typed in user and generate traffic, I don't get a captive portal page and traffic is denied (confirmed via traffic log). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 18:45:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40307#M29581</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-12-24T18:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40308#M29582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sascha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firstly the local db users can be used only after you get the captive portal page (once you get the cp page enter the username that when we get the user to ip mapping ) i.e once the auth is successful that when you can have the policies using the local db users.So i would suggest you to have a sec policy allowing unknown users under the user field select unknown or leave it to any and set the application to web browsing,dns. Then you can have a policy below it with the local user specified and then regulate it accordingly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Subijith Raghunandan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 18:53:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40308#M29582</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-12-24T18:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40309#M29583</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like we're getting closer &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;&amp;nbsp; So why two policies? Can't I put this in one policy? Destination server is HTTP, but operates on port 10001.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 20:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40309#M29583</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-12-24T20:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40310#M29584</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sascha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user is not identified until and unless we have him login to the cp page so in order to get there we need a policy allowing it, and later on once we are identified (ie user to mapping is formed) then the second rules comes in to play.&lt;/P&gt;&lt;P&gt;We always look at the ip of the incoming traffic first and then look to see if there is a mapping for it.&lt;/P&gt;&lt;P&gt;The second policy with the user in can have the dest set to the http server and the port 10001.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Subijith Raghunandan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 20:52:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40310#M29584</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-12-24T20:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40311#M29585</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. I am still puzzeled by the first policy you mention. My understanding was that the captive portal is transparent. So if I set up a rule that requires a user to authenticate, shouldn't captive portal page show up transparently and thus only one policy necessary? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyways... so the first policy is set to unknown user to get the captive portal page to show up. But what do I allow in the first rule and to which destination? If my actual matching rule is supposed to be the second one, what do I put in the first? Sorry, but this kind of evades my logic :smileygrin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 21:04:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40311#M29585</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-12-24T21:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40312#M29586</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Sascha,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The traffic flow is as follows :-&lt;/P&gt;&lt;P&gt;Broswer--type in an url--the traffic hits the pa (at this moment the user is not known to the fw ) it looks at the dest ip and its relevant zone. so first and foremost we need a policy to allow this, once this is allowed the traffic hits the cp policy and the page shows up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Subijith Raghunandan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 21:10:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40312#M29586</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-12-24T21:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Can't select users in policy</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40313#M29587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, say I have two rules:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. src: any, src-user: unknown, dst: webserver-a, app:web-browsing&lt;/P&gt;&lt;P&gt;2. src: any, src-user: my_users, dst: webserver-a, app:web-browsing, port 10001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now the first thing the user does is open &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://webserver-a:10001"&gt;http://webserver-a:10001&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In that case, the first rule would not match and he would never see CP. Did I get that right? If so, the user always has to do something first that is allowed by another rule (in this case rule nr. 1) to be able to trigger CP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Confusing. Or I still don't get it. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Dec 2012 21:33:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-select-users-in-policy/m-p/40313#M29587</guid>
      <dc:creator>cryptochrome</dc:creator>
      <dc:date>2012-12-24T21:33:48Z</dc:date>
    </item>
  </channel>
</rss>

