<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HTTP Header - Logging NTLM Username in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48392#M35612</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My PA firewall inspects traffic between my users and proxy server. The proxy server provides NTLM authentication. Is there a way of logging the NTLM authenticated username within the http headers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Jan 2015 05:23:00 GMT</pubDate>
    <dc:creator>ASCIT</dc:creator>
    <dc:date>2015-01-30T05:23:00Z</dc:date>
    <item>
      <title>HTTP Header - Logging NTLM Username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48392#M35612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My PA firewall inspects traffic between my users and proxy server. The proxy server provides NTLM authentication. Is there a way of logging the NTLM authenticated username within the http headers?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2015 05:23:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48392#M35612</guid>
      <dc:creator>ASCIT</dc:creator>
      <dc:date>2015-01-30T05:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Header - Logging NTLM Username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48393#M35613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ascit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not clear, what you want to achieve. HTTP header is not having a field for user. Could you please explain your requirement here in details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check out this discussion thread:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/message/1983"&gt;Re: Captive portal, manage authenticated users&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2015 07:30:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48393#M35613</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2015-01-30T07:30:00Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Header - Logging NTLM Username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48394#M35614</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/19491"&gt;HULK&lt;/A&gt;, in this instance the PA is not acting as the proxy it sound like.&amp;nbsp; The PA is in between the proxy and the user and is able to inspect that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/u1/30544"&gt;ascit&lt;/A&gt;, I believe that the NTLM portion of the traffic is not within the HTTP header but in a separate NTLM header in the packet.&amp;nbsp; I don't know if the PA would recognize the traffic separately once it ID's the traffic as HTTP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2015 14:06:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48394#M35614</guid>
      <dc:creator>Dz3015</dc:creator>
      <dc:date>2015-01-30T14:06:36Z</dc:date>
    </item>
    <item>
      <title>Re: Re: HTTP Header - Logging NTLM Username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48395#M35615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, I'm hoping to some how log the NTLM User name field:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="ntlm.png" class="image-1 jive-image jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/18107_ntlm.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Feb 2015 05:51:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48395#M35615</guid>
      <dc:creator>ASCIT</dc:creator>
      <dc:date>2015-02-02T05:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Re: HTTP Header - Logging NTLM Username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48396#M35616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ascit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall can not log this specific entry as a straight forward log option.&lt;/P&gt;&lt;P&gt;It can however be inspected to trigger a custom app or custom threat.&lt;/P&gt;&lt;P&gt;Through captive portal the firewall can also provide ntlm user authentication or could be configured to receive syslog from the proxy containing user information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/videos/1317"&gt; Video Link : 1317&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1159"&gt;How to Configure Captive Portal&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-6747"&gt;How to Locate the Predefined Syslog Filters in PAN-OS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hope this helps&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Feb 2015 07:29:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48396#M35616</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2015-02-02T07:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Header - Logging NTLM Username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48397#M35617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG /&gt;&lt;/P&gt;&lt;P&gt;Hi ascit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you just want to identify the user coming from proxy, then there is a way to find out who it is.&lt;/P&gt;&lt;P&gt;Therefor the x-forwarded-for field has to be enabled on proxy and PA.&lt;/P&gt;&lt;P&gt;On PA:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="xff.JPG" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/20101_xff.JPG" style="width: 620px; height: 231px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to find out which ip-adress it is look into the URL-log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Unbenannt.JPG" class="jive-image image-2 jiveImage" src="https://live.paloaltonetworks.com/legacyfs/online/20103_Unbenannt.JPG" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to get filled the URL-log you need the URL-license. Maybe this result is not what you need but that is what is possible right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2015 08:52:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48397#M35617</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2015-06-19T08:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: HTTP Header - Logging NTLM Username</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48398#M35618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ascit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you just want to identify the user coming from proxy, then there is a way to find out who it is.&lt;/P&gt;&lt;P&gt;Therefor the x-forwarded-for field has to be enabled on proxy and PA.&lt;/P&gt;&lt;P&gt;On PA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/showImage/2-53753-20101/xff.JPG"&gt;&lt;IMG alt="xff.JPG" class="image-0 jive-image jiveImage" height="306" src="https://live.paloaltonetworks.com/legacyfs/online/20104_xff.JPG" width="822" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to find out which ip-adress it is look into the URL-log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/servlet/JiveServlet/showImage/2-53753-20103/Unbenannt.JPG"&gt;&lt;IMG alt="Unbenannt.JPG" class="jive-image image-2 jiveImage" height="586" src="https://live.paloaltonetworks.com/legacyfs/online/20105_Unbenannt.JPG" width="1214" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;to get filled the URL-log you need the URL-license. Maybe this result is not what you need but that is what is possible right now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Klaus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Jun 2015 10:16:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/http-header-logging-ntlm-username/m-p/48398#M35618</guid>
      <dc:creator>kdd</dc:creator>
      <dc:date>2015-06-19T10:16:10Z</dc:date>
    </item>
  </channel>
</rss>

