<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Mac OSx &amp; UserID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42560#M31252</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a question. Maybe someone has run across this.&lt;/P&gt;&lt;P&gt;I am using the server monitoring function of Palo&lt;/P&gt;&lt;P&gt;I realize that I can use the user-ID agent and set it to never forget the user mapping, but I am looking for a more accurate way of keeping this mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have mac's that authenticate to a win 2008 domain. Initially I get the user to ip mapping, after the Palo cache expires the mapping is lost. Mac's do not auto update the cache.&lt;/P&gt;&lt;P&gt;My windows machines work normally, The initial mapping is correct and if I use any network resources the user mapping gets updated in Palo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea's, suggestions, etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 17 Jun 2013 14:53:08 GMT</pubDate>
    <dc:creator>Joe_Uriarte</dc:creator>
    <dc:date>2013-06-17T14:53:08Z</dc:date>
    <item>
      <title>Mac OSx &amp; UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42560#M31252</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a question. Maybe someone has run across this.&lt;/P&gt;&lt;P&gt;I am using the server monitoring function of Palo&lt;/P&gt;&lt;P&gt;I realize that I can use the user-ID agent and set it to never forget the user mapping, but I am looking for a more accurate way of keeping this mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have mac's that authenticate to a win 2008 domain. Initially I get the user to ip mapping, after the Palo cache expires the mapping is lost. Mac's do not auto update the cache.&lt;/P&gt;&lt;P&gt;My windows machines work normally, The initial mapping is correct and if I use any network resources the user mapping gets updated in Palo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea's, suggestions, etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 14:53:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42560#M31252</guid>
      <dc:creator>Joe_Uriarte</dc:creator>
      <dc:date>2013-06-17T14:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OSx &amp; UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42561#M31253</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you are using windows machine in AD, you open a session and then after that, periodically, your session is renewed in the AD.&lt;/P&gt;&lt;P&gt;The palo is polling your security event and see, ever you new session and your renew then update is local cahe then you stay authenticated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In Mac world, not sure but , you open a session in AD then generate event then be authen in the palo. After couple of minutes, maybe your Mac doon't ask for session renew then no event in the AD then your authenti expire in the palo.. If you try to access a network ressource, in background you are authenticate again in the domain then you are known by the palo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To be sure, you can check the event in your AD:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Windows 2000/2003:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; SUCCESS_NET_LOGON = 540,&lt;/P&gt;&lt;P&gt;AUTH_TICKET_GRANTED = 672,&lt;/P&gt;&lt;P&gt;SERVICE_TICKET_GRANTED = 673,&lt;/P&gt;&lt;P&gt;TICKET_GRANTED_RENEW = 674,&lt;/P&gt;&lt;P&gt;ACCOUNT_USED_FOR_LOGON = 680,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;Windows 2008:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;LOGON_SUCCESS_W2008 = 4624,&lt;/P&gt;&lt;P&gt;AUTH_TICKET_GRANTED_W2008 = 4768,&lt;/P&gt;&lt;P&gt;TICKET_GRANTED_RENEW_W2008 = 4770,&lt;/P&gt;&lt;P&gt;ACCOUNT_USED_FOR_LOGON_W2008 = 4776,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 17:06:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42561#M31253</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-06-17T17:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OSx &amp; UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42562#M31254</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I agree that is whats happening, except when I use a network resource with the mac, it never creates a new security log.&lt;/P&gt;&lt;P&gt;The resource (mapped share, printer, etc) do work on the mac, but i do not see any security logs being renewed..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did a custom filter on AD log for the mentioned ID events&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Jun 2013 17:57:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42562#M31254</guid>
      <dc:creator>Joe_Uriarte</dc:creator>
      <dc:date>2013-06-17T17:57:42Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OSx &amp; UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42563#M31255</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you access to a windows share (part of domain) for sure, you need authentication.&lt;/P&gt;&lt;P&gt;Try to ad your file server as server in the User-ID client. &lt;/P&gt;&lt;P&gt;I know that the user-ID is able to minotor AD / Exchnage / File server then try that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 18:09:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42563#M31255</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2013-06-18T18:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OSx &amp; UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42564#M31256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great idea, after an initial check this might just work. I was only monitoring my domain controllers. I do see more activity on the specific server for logon request coming from my mac.I will update this tomorrow.... &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Jun 2013 18:41:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42564#M31256</guid>
      <dc:creator>Joe_Uriarte</dc:creator>
      <dc:date>2013-06-18T18:41:23Z</dc:date>
    </item>
    <item>
      <title>Re: Mac OSx &amp; UserID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42565#M31257</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry about the delay int getting back to you Vince, been getting slammed here.&lt;/P&gt;&lt;P&gt;It looks like monitoring the servers did the trick. Thanks for the suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers &lt;/P&gt;&lt;P&gt;-Joe&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 12:33:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/mac-osx-userid/m-p/42565#M31257</guid>
      <dc:creator>Joe_Uriarte</dc:creator>
      <dc:date>2013-06-24T12:33:03Z</dc:date>
    </item>
  </channel>
</rss>

