<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: multiple users same machine privileges crossed in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47226#M34709</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok so some more info&lt;/P&gt;&lt;P&gt;This is only happening on wireless users....wired works fine. we are not seeing a user/ip mapping for the wireless users...the source user is blank&lt;/P&gt;&lt;P&gt;Is there some new feature in 6.0 to help with this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Oct 2014 17:46:40 GMT</pubDate>
    <dc:creator>dthibodeaux</dc:creator>
    <dc:date>2014-10-06T17:46:40Z</dc:date>
    <item>
      <title>multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47223#M34706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #000000; font-family: Calibri; font-size: medium;"&gt;currently have a customer using radius authentication on the wireless and user-id on the PA. The problem is when two different users use the same machine. Teacher logs in and gets a policy applied to the session going through the firewall and she logs out and a student logs in to the same machine, that student has the same privileges through the PA as the teacher did. It seems like the PA is not releasing the session and applying the correct policy to the new user. Any ideas?&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #000000; font-family: Calibri; font-size: medium;"&gt;setup is HA-3020's and Aruba wireless. Radius auth is against microsoft 2012 server&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #000000; font-family: Calibri; font-size: medium;"&gt;Thanks!&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 17:11:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47223#M34706</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2014-10-06T17:11:58Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47224#M34707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/8702"&gt;dthibodeaux&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see the (student) user name in the traffic logs when it hits the policy that you have created for teacher ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, please verify if the ip-user-mapping changes for that IP address after teacher logs out and student logs in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check the ip-user-mapping for an IP using the following command:&lt;/P&gt;&lt;P&gt;show user ip-user-mapping ip &amp;lt;ip/netmask&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 17:16:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47224#M34707</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-06T17:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47225#M34708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dhibodeaux,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually this should not happen, because when user logs out, it creates a security log on AD server. Firewall reads it and remove the mapping. We should try to find out why its not happenning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, there are two solution for this.&lt;/P&gt;&lt;P&gt;1. Reduce Timeout interval for user-id to ip mapping. - Which means older mappings will expire if there is no activity from them.&lt;/P&gt;&lt;P&gt;2. Or enable WMI probing - User-id agent queries all active users, if they dont respond. Its removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;HArdik Shah: &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 17:17:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47225#M34708</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-10-06T17:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47226#M34709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok so some more info&lt;/P&gt;&lt;P&gt;This is only happening on wireless users....wired works fine. we are not seeing a user/ip mapping for the wireless users...the source user is blank&lt;/P&gt;&lt;P&gt;Is there some new feature in 6.0 to help with this?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 17:46:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47226#M34709</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2014-10-06T17:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47227#M34710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/8702"&gt;dthibodeaux&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source user field is blank due to the username not being pushed correctly, how are you pushing the usernames from the Aruba wireless&amp;nbsp; ? Are you using XML API ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 17:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47227#M34710</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-06T17:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47228#M34711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm guessing I'm not...:smileyconfused:&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 17:58:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47228#M34711</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2014-10-06T17:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47229#M34712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are multiple methods to push user ip mappings:&lt;/P&gt;&lt;P&gt;--Using a syslog parser profile:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6727"&gt;How to Collect the User-IP Mappings from a Syslog Sender Using an User-ID Agent&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Using XML API:&lt;/P&gt;&lt;P&gt;&lt;A href="https://paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/technology-solutions-briefs/aruba.pdf" title="https://paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/technology-solutions-briefs/aruba.pdf"&gt;https://paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/assets/pdf/technology-solutions-briefs/aruba.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.arubanetworks.com/wp-content/uploads/TechNote_ArubaAndPaloAltoNetworksIntegration.pdf" title="http://www.arubanetworks.com/wp-content/uploads/TechNote_ArubaAndPaloAltoNetworksIntegration.pdf"&gt;http://www.arubanetworks.com/wp-content/uploads/TechNote_ArubaAndPaloAltoNetworksIntegration.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 18:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47229#M34712</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-06T18:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47230#M34713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you have to use api or the new syslog feature as mentioned.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Oct 2014 18:48:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47230#M34713</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2014-10-06T18:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47231#M34714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok so this customer does not have clear pass so I am assuming the xml api solution wont work...as far as the syslog solution, I am trying to set this up in my lab. I have a aruba controller, pa200, and 2008 server. Do I run the syslog server on the same server as the user-id agent is on or do these need to be separate boxes? I am running kiwi syslog server on the same 2008 server as the UID agent is on...think I said that already &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://live.paloaltonetworks.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;The document keeps referring to a "syslog sender" and I am not sure if that is the controller, the PA, or the 2008 server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;David &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 15:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47231#M34714</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2014-10-08T15:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47232#M34715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/8702"&gt;dthibodeaux&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syslog sender should be aruba controller which should be sending login/logout events to pa200. On pa200 you should have syslog parser profile to parse these logs and extract the User to IP information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 16:23:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47232#M34715</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2014-10-08T16:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47233#M34716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did finally get this to work using the user-id agent setup on the PA itself but my concern is how taxing this might be to the box in a production environment. I would really like it to work using the user-id agent on the domain controller. For some reason I cannot get the info from the DC to the PA for the wireless users. I have the Aruba pointing at the DC where the agent resides, I have the agent setup with the sender info but never see the user info on the PA in the monitor logs. any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Oct 2014 18:22:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47233#M34716</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2014-10-08T18:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: multiple users same machine privileges crossed</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47234#M34717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok I got it working using the UID agent residing on the DC.&lt;/P&gt;&lt;P&gt;Thanks for all the info!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Oct 2014 13:59:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-users-same-machine-privileges-crossed/m-p/47234#M34717</guid>
      <dc:creator>dthibodeaux</dc:creator>
      <dc:date>2014-10-10T13:59:07Z</dc:date>
    </item>
  </channel>
</rss>

