<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41399#M30432</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could send the cisco syslog to another pc (with access to the mgmt of the PA) which could parse the logs and then through the XML API of the PA device (RESTFUL api) insert which user is currently using which IP if im not mistaken.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 01 Dec 2013 17:49:45 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2013-12-01T17:49:45Z</dc:date>
    <item>
      <title>WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41390#M30423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm thinking about WiFi network for my studnets. Now they are authenticating on HotSpot on Mikrotik AP's. They are complaining that must enter login and password so often.&lt;/P&gt;&lt;P&gt;HotSpot also isn't good for me becase I can't see authenticated users in PAN logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to configure 802.1x authentication on AP and have in logs proper user name of logged user that is using IP attached from PAN DHCP?&lt;/P&gt;&lt;P&gt;Authentication is made by Radius (Free Radius) - not by Active Directory!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If my idea is bad, please advice me how to do that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ragards&lt;/P&gt;&lt;P&gt;Slawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 09:50:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41390#M30423</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-24T09:50:36Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41391#M30424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Slawek,&lt;/P&gt;&lt;P&gt;You can force the students to authenticate against captive portal. They can be authenticated against a radius server, although it is not necessary to configure the radius auth on the AP. You can have a dedicated radius server for the authentication. With captive portal configuration, the students would have to enter the credentials just once, and they need not login multiple times ( unless they close the browser itself, and then they would be prompted for authentication again). Since captive portal works for&amp;nbsp; users that do not have IP-user mapping information relayed to the firewall from the agent or agentless service, you can create a new zone for the wifi network and disable user-identification on that zone. You can find below the document that explains how to setup captive portal, and the configuring the captive portal to use radius authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1159"&gt;https://live.paloaltonetworks.com/docs/DOC-1159&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1410"&gt;https://live.paloaltonetworks.com/docs/DOC-1410&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 13:40:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41391#M30424</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-24T13:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41392#M30425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;The following Doc talks about &lt;SPAN style="font-style: inherit; font-size: 12.222222328186035px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;Radius (Cisco ACS)&lt;/SPAN&gt; and User-ID integration in the environments using 802.1x devices and wireless access points and controllers.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;SPAN style="font-style: inherit; font-size: 10pt; font-family: inherit;"&gt;A script can be &lt;/SPAN&gt;configured to run on the Syslog server that will extract the user and IP information from the message, format it correctly for the UID-API, and then send it to the API agent.&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;A _jive_internal="true" data-containerid="2010" data-containertype="14" data-objectid="1936" data-objecttype="102" href="https://live.paloaltonetworks.com/docs/DOC-1936" style="font-style: inherit; font-family: inherit; color: #316989;"&gt;UserID API integration using Syslog&lt;/A&gt;&lt;/P&gt;&lt;P style="font-size: 12px; font-family: Arial, Helvetica, sans-serif; color: #000000; background-color: #ffffff;"&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check :&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/thread/7239"&gt;https://live.paloaltonetworks.com/thread/7239&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 08:18:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41392#M30425</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-06-25T08:18:07Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41393#M30426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;You can force the students to authenticate against captive portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know. I'm using CP for test purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;the students would have to enter the credentials just once, and they need not login multiple times&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know, logon from notebook is OK, but do it from smarfones - it so compicated (in my opinion, because smarphones has a small screen and etc).&lt;/P&gt;&lt;P&gt;Students want to be connected without enter credential every time he is in wiFi range. So that is the reason why I'm started thinking about 802.1x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 09:28:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41393#M30426</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-25T09:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41394#M30427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;gt;The following Doc talks about &lt;SPAN style="font-style: inherit; font-size: 12.222222328186035px; font-family: 'Lucida Grande', 'Helvetica Neue', Helvetica, Arial, sans-serif;"&gt;Radius (Cisco ACS)&lt;/SPAN&gt; and User-ID integration in the environments using 802.1x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;uff - I expected simplest way to do it. Syslog server isn't a problem but as I remember that API uses administrator provilages of PAN, I wouldn't share that credentials.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 09:38:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41394#M30427</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-25T09:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41395#M30428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could use user-ID XML API of User-ID agent on a windows PC?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 13:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41395#M30428</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2013-06-25T13:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41396#M30429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you explain a bit?&lt;/P&gt;&lt;P&gt;I found only &lt;A __default_attr="4423" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My Radius is a Free Radius on Linux server - how can I read logs from them? I'm going to implement Splunk - but not now (I hope) - I have a lot of other things to do.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 13:24:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41396#M30429</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-06-25T13:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41397#M30430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry was in response to your statement "&lt;SPAN style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; background-color: #ffffff;"&gt;Syslog server isn't a problem but as I remember that API uses administrator provilages of PAN, I wouldn't share that credentials&lt;/SPAN&gt;". I don't think you need PAN credentials if you use the user-id agent. The firewall API requires an username and password to upload user mappings. The software user-id agent running on a windows PC does not need PAN admin credentials to upload user mappings. You only need to configure the connection between the user-id agent and the firewall. The script extracts user to IP mappings and injects it to the user-id agent running on windows. Hope my explanation makes sense &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Jun 2013 13:38:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41397#M30430</guid>
      <dc:creator>Quinton</dc:creator>
      <dc:date>2013-06-25T13:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41398#M30431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a shame we can't have the cisco controllers send syslogs to PAN and PAN decode's them itself for which user just got which IP...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 23:03:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41398#M30431</guid>
      <dc:creator>MydisplayNameis3</dc:creator>
      <dc:date>2013-11-05T23:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: WiFi with 802.1x and Radius authentication - source user in traffic log problem</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41399#M30432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could send the cisco syslog to another pc (with access to the mgmt of the PA) which could parse the logs and then through the XML API of the PA device (RESTFUL api) insert which user is currently using which IP if im not mistaken.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Dec 2013 17:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wifi-with-802-1x-and-radius-authentication-source-user-in/m-p/41399#M30432</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-12-01T17:49:45Z</dc:date>
    </item>
  </channel>
</rss>

