<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: for what purpose would the management interface use msrpc? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48104#M35371</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have Agentless UserID configured on your firewall? If so, we need to make sure that we disable Client probing under Device &amp;gt; User Identification &amp;gt; User Mapping &amp;gt; Client probing tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Sep 2013 20:47:59 GMT</pubDate>
    <dc:creator>kadak</dc:creator>
    <dc:date>2013-09-26T20:47:59Z</dc:date>
    <item>
      <title>for what purpose would the management interface use msrpc?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48103#M35370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the mgmt interface on a 3050 is reaching out to a number of internal host over msrpc (tcp/135). i've not been successful in discoving the purpose of this via the admin guide - is anyone else seeing this behavior?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx,&lt;/P&gt;&lt;P&gt;tommyluke&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2013 20:05:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48103#M35370</guid>
      <dc:creator>tommyluke</dc:creator>
      <dc:date>2013-09-26T20:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: for what purpose would the management interface use msrpc?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48104#M35371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have Agentless UserID configured on your firewall? If so, we need to make sure that we disable Client probing under Device &amp;gt; User Identification &amp;gt; User Mapping &amp;gt; Client probing tab.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2013 20:47:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48104#M35371</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-26T20:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: for what purpose would the management interface use msrpc?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48105#M35372</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you kadak. You are correct, I have agentless userid configured. I imagine that, were I to disable client probing, the msrpc data from the management ip would cease. When you stat that we need to "make sure that we disabled client probing" is that because you have experienced problems with client probing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;best,&lt;/P&gt;&lt;P&gt;tommy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2013 21:13:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48105#M35372</guid>
      <dc:creator>tommyluke</dc:creator>
      <dc:date>2013-09-26T21:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: for what purpose would the management interface use msrpc?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48106#M35373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Tom,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I meant was, we haven't seen any problems/ issues per say - after enabling 'Client Probing' in Agentless setup.&amp;nbsp; It just that we saw un-wanted WMI probes from the User-ID function on port 135.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In fact after further investigation, it looks like the issue has been taken care of in PANOS - 5.0.7&amp;nbsp; and you can verify that in its release notes by 52967.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kunal Adak.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Sep 2013 21:37:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/for-what-purpose-would-the-management-interface-use-msrpc/m-p/48106#M35373</guid>
      <dc:creator>kadak</dc:creator>
      <dc:date>2013-09-26T21:37:54Z</dc:date>
    </item>
  </channel>
</rss>

