<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: X FORWARD FOR  with USER ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47950#M35246</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Do I understand correctly that you want to retrieve the client IP via "x-forwarded for" and then let the PA use its User-ID to map this IP to a user?&lt;/P&gt;&lt;P&gt;I don't think this will be possible, based on the DOC provided by kdd, since the client IP will be "written" in the "source user" column. &lt;/P&gt;&lt;P&gt;Looks like a nice feature request to me though. Kind of like the Terminal Services User-ID agent can identify users based on source port, maybe a Proxy User-ID agent that can find users based on "x-forwarded for"...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 Jan 2014 11:13:53 GMT</pubDate>
    <dc:creator>mr.linus</dc:creator>
    <dc:date>2014-01-29T11:13:53Z</dc:date>
    <item>
      <title>X FORWARD FOR  with USER ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47948#M35244</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it possible to use ip retrieved from the x forwarded&amp;nbsp; header and combined with the user-id.&lt;/P&gt;&lt;P&gt;my aim is to filter access per active directorie usergroup, but I have a proxy implemented between the palo and the user device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 08:55:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47948#M35244</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2014-01-29T08:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: X FORWARD FOR  with USER ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47949#M35245</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gregoux,&lt;/P&gt;&lt;P&gt;the links explain how to enable it and how it will work&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-1128"&gt;https://live.paloaltonetworks.com/docs/DOC-1128&lt;/A&gt;&lt;/P&gt;&lt;P&gt;instead of CLI via browser Device &amp;gt; Setup &amp;gt; Content-ID&lt;/P&gt;&lt;P&gt;The "strip x-forwarded for" option replaces the ip-address with zeros. so that the destination is not able to see the clients ip-address&lt;/P&gt;&lt;P&gt;Regards Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 10:55:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47949#M35245</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2014-01-29T10:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: X FORWARD FOR  with USER ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47950#M35246</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Do I understand correctly that you want to retrieve the client IP via "x-forwarded for" and then let the PA use its User-ID to map this IP to a user?&lt;/P&gt;&lt;P&gt;I don't think this will be possible, based on the DOC provided by kdd, since the client IP will be "written" in the "source user" column. &lt;/P&gt;&lt;P&gt;Looks like a nice feature request to me though. Kind of like the Terminal Services User-ID agent can identify users based on source port, maybe a Proxy User-ID agent that can find users based on "x-forwarded for"...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Jan 2014 11:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47950#M35246</guid>
      <dc:creator>mr.linus</dc:creator>
      <dc:date>2014-01-29T11:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: X FORWARD FOR  with USER ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47951#M35247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also need to retrieve the "source user" who under the PROXY.&lt;/P&gt;&lt;P&gt;Now, I find the user name by check "user_ip_map" and "x-forwarded for".&lt;/P&gt;&lt;P&gt;But this is very very heavy work..&lt;/P&gt;&lt;P&gt;If PAN create new columns "x-forwarded for" and "x-forwarded for user" like "source" and "source user " in traffic log &amp;amp; URL Filtering log,&lt;/P&gt;&lt;P&gt;it is very helpful and much enough for my need.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jan 2014 01:37:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/x-forward-for-with-user-id/m-p/47951#M35247</guid>
      <dc:creator>Mt_103</dc:creator>
      <dc:date>2014-01-30T01:37:25Z</dc:date>
    </item>
  </channel>
</rss>

