<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID from eDirectory, multiple IPs per user in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44004#M32301</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;The firewall gets the ip-user-mapping from either the agent or through the agentless-service, based on the log on events from the DC or from the edirectory. The agent or the service can hold multiple ip-user mappings for the same user, but from different machines (ip addresses). We should also see the multiple entries for the user on the agent or the firewall (agentless service). Can you increase the timeout of the ip-user-mapping on the agent, so that the entries are not cleared at a faster rate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its common to see unknowns under the "show user ip-user mapping all" command. This mapping is seen when the firewall does not have information about an IP address from the agent/agentless service, and those users for whom captive portal isnt defined for. You can force the firewall to query the agent/ agentless service to actively probe for these unknown IP addresses using the netbios or wmi probing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The below documents explains the recommended steps for user identifictaion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1052"&gt;https://live.paloaltonetworks.com/docs/DOC-1052&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4534"&gt;https://live.paloaltonetworks.com/docs/DOC-4534&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 24 Jun 2013 16:29:51 GMT</pubDate>
    <dc:creator>kprakash</dc:creator>
    <dc:date>2013-06-24T16:29:51Z</dc:date>
    <item>
      <title>User ID from eDirectory, multiple IPs per user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44003#M32300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for identifying users on an PA-3020 with PAN-OS 5.0.5 I use a combination of reading the information from eDirectory, XML-API and captive portal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now facing the problem that users which use different computers at the same time with their user account which is authenticated against the eDirectory (for example one at their workplace and another one during a meeting in another room), only the first IP which is known to the eDirectory is authenticated on the firewall (but both IPs are available in the eDirectory if I check for them using a simple LDAP browser or novell console one) and the captive portal is shown to the user (in best case, also got reports that in some cases just the block response page got prompted)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also I have sometimes entries for source "Unknown" and user "Unknown" if I list the user mappings on the device using "show user ip-user-mapping all".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that a known problem or more a kind of feature? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stefan Steinert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 15:28:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44003#M32300</guid>
      <dc:creator>StefanSteinert</dc:creator>
      <dc:date>2013-06-24T15:28:55Z</dc:date>
    </item>
    <item>
      <title>Re: User ID from eDirectory, multiple IPs per user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44004#M32301</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stefan,&lt;/P&gt;&lt;P&gt;The firewall gets the ip-user-mapping from either the agent or through the agentless-service, based on the log on events from the DC or from the edirectory. The agent or the service can hold multiple ip-user mappings for the same user, but from different machines (ip addresses). We should also see the multiple entries for the user on the agent or the firewall (agentless service). Can you increase the timeout of the ip-user-mapping on the agent, so that the entries are not cleared at a faster rate. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its common to see unknowns under the "show user ip-user mapping all" command. This mapping is seen when the firewall does not have information about an IP address from the agent/agentless service, and those users for whom captive portal isnt defined for. You can force the firewall to query the agent/ agentless service to actively probe for these unknown IP addresses using the netbios or wmi probing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The below documents explains the recommended steps for user identifictaion&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" class="active_link" href="https://live.paloaltonetworks.com/docs/DOC-1052"&gt;https://live.paloaltonetworks.com/docs/DOC-1052&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4534"&gt;https://live.paloaltonetworks.com/docs/DOC-4534&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Jun 2013 16:29:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44004#M32301</guid>
      <dc:creator>kprakash</dc:creator>
      <dc:date>2013-06-24T16:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: User ID from eDirectory, multiple IPs per user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44005#M32302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for that suggestion. I will try that next week as soon as I have again access to the system.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Jul 2013 05:58:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44005#M32302</guid>
      <dc:creator>StefanSteinert</dc:creator>
      <dc:date>2013-07-01T05:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: User ID from eDirectory, multiple IPs per user</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44006#M32303</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, played around with the timeout settings of the agentless service of the device but had no success. The device still sees only one IP address from the edirectory.&lt;/P&gt;&lt;P&gt;For testing I have installed the User-ID Agent on one of my clients, which then is able to see both IP addresses, also the device is able to see both IPs if I add the Agent to the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess that there is an bug in the implementation of the agentless service on the device that it only retrieves one IP from the e-directory &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jul 2013 07:04:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-from-edirectory-multiple-ips-per-user/m-p/44006#M32303</guid>
      <dc:creator>StefanSteinert</dc:creator>
      <dc:date>2013-07-19T07:04:05Z</dc:date>
    </item>
  </channel>
</rss>

