<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PaloAlto integrate with AD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-integrate-with-ad/m-p/45522#M33445</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;When I configured authentication on&amp;nbsp; PaloAlto I met the problem:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I tested authentication on&amp;nbsp; PaloAlto:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;- 1 Domain Server: installed PAN Agent &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;- 2 pc join&amp;nbsp; domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;- Create some accounts: user1,&amp;nbsp; user2, user3&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;1&amp;gt; I logon with domain user&amp;nbsp; (user1), I can access Internet and in Monitor Tab I can see my pc had been&amp;nbsp; authenticated (user_domain.png)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;2&amp;gt; I logout and login again with&amp;nbsp; local user (cloud), I still can access Internet (user_Local.png) although I set&amp;nbsp; policy deny all except user1, user2 (policy.png)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;3&amp;gt; If I changed IP Address from&amp;nbsp; 172.16.1.71 to 172.16.1.76, I couldn’t access Internet but If I changed IP&amp;nbsp; Address to 172.16.1.71, I still access Internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -0.25in; margin-left: 0.5in;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings; "&gt;&lt;SPAN&gt;-&lt;SPAN style="font: 7pt 'Times New Roman'; font-size: 8pt; font-family: Times New Roman; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I want only domain user can access&amp;nbsp; Internet but local user, PaloAlto can do or not?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -0.25in; margin-left: 0.5in;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings; "&gt;&lt;SPAN&gt;-&lt;SPAN style="font: 7pt 'Times New Roman'; font-size: 8pt; font-family: Times New Roman; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I think PaloAlto cached the IP&amp;nbsp; Address to define Account Domain so when I logon with local user with old IP&amp;nbsp; Address, I still access Internet. If I right, how long PaloAlto will clear&amp;nbsp; cache? Can I change the time to clear?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -0.25in; margin-left: 0.5in;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings; "&gt;&lt;SPAN&gt;-&lt;SPAN style="font: 7pt 'Times New Roman'; font-size: 8pt; font-family: Times New Roman; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I used PC1 to access Internet with&amp;nbsp; user1 but I still could&amp;nbsp; used PC2 to access Internet with user1. PC1 and PC2&amp;nbsp; could access Internet in the same time with the same user. Can I configure&amp;nbsp; PaloAlto allow only one user to access Internet?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 22 Mar 2010 04:22:16 GMT</pubDate>
    <dc:creator>Ovan</dc:creator>
    <dc:date>2010-03-22T04:22:16Z</dc:date>
    <item>
      <title>PaloAlto integrate with AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-integrate-with-ad/m-p/45522#M33445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;When I configured authentication on&amp;nbsp; PaloAlto I met the problem:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I tested authentication on&amp;nbsp; PaloAlto:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;- 1 Domain Server: installed PAN Agent &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;- 2 pc join&amp;nbsp; domain&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;- Create some accounts: user1,&amp;nbsp; user2, user3&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;1&amp;gt; I logon with domain user&amp;nbsp; (user1), I can access Internet and in Monitor Tab I can see my pc had been&amp;nbsp; authenticated (user_domain.png)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;2&amp;gt; I logout and login again with&amp;nbsp; local user (cloud), I still can access Internet (user_Local.png) although I set&amp;nbsp; policy deny all except user1, user2 (policy.png)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;3&amp;gt; If I changed IP Address from&amp;nbsp; 172.16.1.71 to 172.16.1.76, I couldn’t access Internet but If I changed IP&amp;nbsp; Address to 172.16.1.71, I still access Internet.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -0.25in; margin-left: 0.5in;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings; "&gt;&lt;SPAN&gt;-&lt;SPAN style="font: 7pt 'Times New Roman'; font-size: 8pt; font-family: Times New Roman; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I want only domain user can access&amp;nbsp; Internet but local user, PaloAlto can do or not?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -0.25in; margin-left: 0.5in;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings; "&gt;&lt;SPAN&gt;-&lt;SPAN style="font: 7pt 'Times New Roman'; font-size: 8pt; font-family: Times New Roman; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I think PaloAlto cached the IP&amp;nbsp; Address to define Account Domain so when I logon with local user with old IP&amp;nbsp; Address, I still access Internet. If I right, how long PaloAlto will clear&amp;nbsp; cache? Can I change the time to clear?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="text-indent: -0.25in; margin-left: 0.5in;"&gt;&lt;SPAN style="font-size: 10pt; font-family: Wingdings; "&gt;&lt;SPAN&gt;-&lt;SPAN style="font: 7pt 'Times New Roman'; font-size: 8pt; font-family: Times New Roman; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt; font-family: Arial; "&gt;I used PC1 to access Internet with&amp;nbsp; user1 but I still could&amp;nbsp; used PC2 to access Internet with user1. PC1 and PC2&amp;nbsp; could access Internet in the same time with the same user. Can I configure&amp;nbsp; PaloAlto allow only one user to access Internet?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Mar 2010 04:22:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-integrate-with-ad/m-p/45522#M33445</guid>
      <dc:creator>Ovan</dc:creator>
      <dc:date>2010-03-22T04:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: PaloAlto integrate with AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/paloalto-integrate-with-ad/m-p/45523#M33446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The PANAgent is looking for users logged into the domain and won't detect if a user is changed to "local."&amp;nbsp; As long as that IP remains active, the PANAgent thinks the original domain user is logged in. Even when using Netbios probing, the original domain login is chached (even if actually logged out) on the workstation and the Panagent will continue to see the original domain login.&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.1 may be an option for you as it will allow you to use WMI instead of Netbios and user activity will be correctly read.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Mar 2010 01:40:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/paloalto-integrate-with-ad/m-p/45523#M33446</guid>
      <dc:creator>nrice</dc:creator>
      <dc:date>2010-03-25T01:40:30Z</dc:date>
    </item>
  </channel>
</rss>

