<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem of Authenticating users on Cisco WLC integrated with Palo alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41461#M30492</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is the same configuration on PA&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Untitled.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20608_Untitled.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Aug 2015 07:06:07 GMT</pubDate>
    <dc:creator>AhmedSheta</dc:creator>
    <dc:date>2015-08-05T07:06:07Z</dc:date>
    <item>
      <title>Problem of Authenticating users on Cisco WLC integrated with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41457#M30488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;dear all, &lt;/P&gt;&lt;P&gt;we have integrated our Cisco Wireless Controller with Palo alto Firewall, the problem is that &lt;SPAN style="text-decoration: underline;"&gt;some people&lt;/SPAN&gt;, authenticated successfully on the network, but the username still not appeare&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;s on Palo alto, although i can found them on the WLC, this happening with few users, not all&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2015 06:45:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41457#M30488</guid>
      <dc:creator>AhmedSheta</dc:creator>
      <dc:date>2015-08-05T06:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of Authenticating users on Cisco WLC integrated with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41458#M30489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Can you explain more, how you are authenticating user on the WLC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you using 802.1x?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2015 06:49:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41458#M30489</guid>
      <dc:creator>SajidAliSajid</dc:creator>
      <dc:date>2015-08-05T06:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of Authenticating users on Cisco WLC integrated with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41459#M30490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes exactly, and i am creating Trap receivers which send all traps to kiwi syslog and the kiwi syslog is sending the firewall.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2015 06:50:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41459#M30490</guid>
      <dc:creator>AhmedSheta</dc:creator>
      <dc:date>2015-08-05T06:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of Authenticating users on Cisco WLC integrated with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41460#M30491</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;its depend of the Cisco WLC version.&lt;/P&gt;&lt;P&gt;Version 8.0 sends Traps with OID enterprise=1.3.6.1.4.1.9.9.599.0.4&lt;/P&gt;&lt;P&gt;Username prefix: 1.3.6.1.4.1.9.9.599.1.3.1.1.27.0=&lt;/P&gt;&lt;P&gt;cldcClientIPAddress.0=&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for cisco wlc 7&lt;/P&gt;&lt;P&gt;enterprise=1.3.6.1.4.1.9.9.599.0.4&lt;/P&gt;&lt;P&gt;cldcClientUsername.0=&lt;/P&gt;&lt;P&gt;cldcClientIPAddress.0=&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try PAN agent as well to parse UserID and IP address.&lt;/P&gt;&lt;P&gt;Same data can be fetch from Radius.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Cisco generate different OIDs for authentication (I am not expert on Cisco WLC).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2015 07:00:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41460#M30491</guid>
      <dc:creator>SajidAliSajid</dc:creator>
      <dc:date>2015-08-05T07:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of Authenticating users on Cisco WLC integrated with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41461#M30492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is the same configuration on PA&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Untitled.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20608_Untitled.jpg" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2015 07:06:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41461#M30492</guid>
      <dc:creator>AhmedSheta</dc:creator>
      <dc:date>2015-08-05T07:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem of Authenticating users on Cisco WLC integrated with Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41462#M30493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the following documnets&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-6727" title="https://live.paloaltonetworks.com/docs/DOC-6727"&gt;https://live.paloaltonetworks.com/docs/DOC-6727&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-8490"&gt;HOWTO: User-IP Mapping from Cisco WLC RADIUS Accounting Massage&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have to check the sys log messages and based on the messages. You have to select three vaules&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;gt; Event String&lt;/P&gt;&lt;P&gt;2&amp;gt;Username Prefix&lt;/P&gt;&lt;P&gt;3&amp;gt;Address Prefix&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These values tells to firewall that an authentication event starts from &amp;lt;Event string value&amp;gt; and the username can be fetched from &amp;lt;Username Prefix&amp;gt; and the IP address of the user is &amp;lt;Address Prefix&amp;gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;2013-03-20 12:56:53 local4.notice Aruba-Local3 authmgr[1568]: &amp;lt;522008&amp;gt; &amp;lt;NOTI&amp;gt; &amp;lt;Aruba-Local3 10.200.10.10&amp;gt;&amp;nbsp; User Authentication Successful: username=ilija MAC=78:f5:fd:dd:ff:90 IP=10.200.27.67&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Every authentication event have one string common that is "User Authentication Successful". Now the Username is "ilija" and the IP address is "10.200.27.67". We have to guide the PA firewall such that firewall can get the desired information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Rate the helpful answer.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Aug 2015 07:31:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/problem-of-authenticating-users-on-cisco-wlc-integrated-with/m-p/41462#M30493</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2015-08-05T07:31:04Z</dc:date>
    </item>
  </channel>
</rss>

