<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User Identification Timeout - What to do ? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44014#M32311</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Palo Alto consolidated and working fine in my network but sometimes I have to do some changes on AD groups to give some rights to some users...&lt;/P&gt;&lt;P&gt;I am realizing that all changes delays too much to take effect in Palo Alto, I think is because my agent have user identification timeout set to 45 minutes..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words Palo ALto delays around 45 minutes to realize any change into AD groups... right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking in decrease that value to 5 minutes... What is the impact having user identification timeout set to 5 minutes ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot128.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3944_ScreenShot128.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All my DC are located inside my network, no remote DCs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Sep 2012 17:54:08 GMT</pubDate>
    <dc:creator>FabioGarcia</dc:creator>
    <dc:date>2012-09-04T17:54:08Z</dc:date>
    <item>
      <title>User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44014#M32311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dears, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Palo Alto consolidated and working fine in my network but sometimes I have to do some changes on AD groups to give some rights to some users...&lt;/P&gt;&lt;P&gt;I am realizing that all changes delays too much to take effect in Palo Alto, I think is because my agent have user identification timeout set to 45 minutes..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words Palo ALto delays around 45 minutes to realize any change into AD groups... right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking in decrease that value to 5 minutes... What is the impact having user identification timeout set to 5 minutes ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot128.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3944_ScreenShot128.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All my DC are located inside my network, no remote DCs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 17:54:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44014#M32311</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2012-09-04T17:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44015#M32312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User identification timeout is nothing but timeout value for user entries. You might want to change the security log timer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;Subijith Raghunandan.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 18:28:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44015#M32312</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-09-04T18:28:01Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44016#M32313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shouldnt a decreased TTL for the various caches slightly increase the load for the mgmtplane?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 18:40:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44016#M32313</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-09-04T18:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44017#M32314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, you meant I should keep 45 minutes and focus on security log timer ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But sec log timer is already set to 1 second....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now I am doint tests with my login....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a rule allowing social networking for some AD group "social_networking_allowed"...&lt;/P&gt;&lt;P&gt;I have just added my user to that group and till now I am still not able to be allowed to social networks sites...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is that usual this behavior... whenever I add or take off some user from an AD group that will delay all this time to reflect on PA rules ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below my agent config&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ScreenShot129.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/3945_ScreenShot129.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 18:45:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44017#M32314</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2012-09-04T18:45:45Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44018#M32315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does the newly added user show up in the PA, please use the following command:- &amp;gt; show user group name (name)&amp;nbsp; and also paste the following command o/ps&amp;nbsp; &amp;gt;show user group-mapping statistics and&amp;nbsp; show user group-mapping state all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 18:56:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44018#M32315</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-09-04T18:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44019#M32316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;fabio.garcia@XXXXXXXX(active)&amp;gt; show user group name "XXXXXXXXX\redes sociais - allow"&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;[30&amp;nbsp;&amp;nbsp;&amp;nbsp; ] XXXXXXXX\fabio.garcia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Even after 15 minutes I took off my name from that AD group I am still seeing my name over there...&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;####################################################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fabio.garcia@XXXXXXXXX(active)&amp;gt; show user group-mapping statistics&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vsys&amp;nbsp;&amp;nbsp;&amp;nbsp; Groups Last-Action(secs)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next-Action(secs)&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;XXXXX-XXXXX&amp;nbsp; vsys1&amp;nbsp;&amp;nbsp; 7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1859 secs ago(took 0 secs)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In 1741 secs&lt;EM&gt;&lt;STRONG&gt; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; ??? &lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Is that the delay till PA checks again users inside all groups ???&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#####################################################&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fabio.garcia@XXXXXXX(active)&amp;gt; show user group-mapping state all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group Mapping(vsys1, type: active-directory): XXXX-XXXXX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bind DN&amp;nbsp;&amp;nbsp;&amp;nbsp; : ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Filter: (None)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Filter: (None)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Servers&amp;nbsp;&amp;nbsp;&amp;nbsp; : configured 2 servers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; X.X.X.X(389)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: 1932 secs ago(took 0 secs)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;Next Action Time: In 1668 secs&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; X.X.X.X(389)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 19:20:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44019#M32316</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2012-09-04T19:20:49Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44020#M32317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got it....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In GUI&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Device &amp;gt; User identification (left menu) &amp;gt; Group Mapping Setings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clicking at your SERVER configured, then UPDATE INTERVAL I choose 60 (seconds)....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I delay maximum of 60 seconds to PA updates list of AD groups (with new users or deleted users)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 19:39:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44020#M32317</guid>
      <dc:creator>FabioGarcia</dc:creator>
      <dc:date>2012-09-04T19:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44021#M32318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's Great i was about to reply was caught up on a cal, now is this working as expected.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2012 19:45:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44021#M32318</guid>
      <dc:creator>sraghunandan</dc:creator>
      <dc:date>2012-09-04T19:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: User Identification Timeout - What to do ?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44022#M32319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I feel that the default values in the doc mentioned earlier are a bit high - but I guess there is some good reason behind each setting for why its so high.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the most aggressive settings that are still fine to use regarding mgmtplane utilization etc?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because I have a bad feeling that something would break if one select the lowest values for each item like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Age-out timeout: 1min&lt;/P&gt;&lt;P&gt;User membership timeout: 1min&lt;/P&gt;&lt;P&gt;Security log timer: 1sec&lt;/P&gt;&lt;P&gt;Netbios probing (is the same as for wmi?): 1min&lt;/P&gt;&lt;P&gt;Server session timer: 1sec&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Sep 2012 08:29:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-timeout-what-to-do/m-p/44022#M32319</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-09-05T08:29:05Z</dc:date>
    </item>
  </channel>
</rss>

