<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL VPN and User identification in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4905#M3600</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the SSL VPN login will populate the traffic, threat, url, etc. logs with User-ID information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 15 Dec 2010 23:37:32 GMT</pubDate>
    <dc:creator>kbrazil</dc:creator>
    <dc:date>2010-12-15T23:37:32Z</dc:date>
    <item>
      <title>SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4900#M3595</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When a user is logged on to the SSL VPN through my Palo Alto firewalls, the user dientification seems to be - well, flakey.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sometimes it identifies, most of the time it doesn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have "Enable User Identification" ticked on the VPN zone, yet I am seeing traffic into the network through the VPN which doesn;t identify the source user - yet the user is plainly identifiable by viewing the current users logged on to the VPN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interestingly, when the user initially logged on to the VPN this morning, every packet was identified for about the first hour and 20 minutes, ten the identification became interrmittent and only occurs every few packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if this is some inherent timer, or is there something I can tweak to get this working all the time?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Dec 2010 00:01:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4900#M3595</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2010-12-07T00:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4901#M3596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not aware of any timer issues?&amp;nbsp; What software version are you currently running on your pan-agent and how many do you have? &lt;/P&gt;&lt;P&gt;Try resetting your pan-agent connection to your PAN device and see if that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 22:20:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4901#M3596</guid>
      <dc:creator>odaos</dc:creator>
      <dc:date>2010-12-08T22:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4902#M3597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;odaos wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not aware of any timer issues?&amp;nbsp; What software version are you currently running on your pan-agent and how many do you have? &lt;/P&gt;&lt;P&gt;Try resetting your pan-agent connection to your PAN device and see if that helps.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The box is running 3.1.6 software, and the VPN client is 1.2.0. Agent version is 3.1.2, all of which are the latest available as far as I can tell (well, there was a beta version of PanOS 4 which popped up in te software list the other day, but I definitely did NOT install it, and it's gone now).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've removed/re-added the user agent connection - but haven't had a long-term VPN user logon since, so I have to wait until one of my more common "work from home" users logs back in. I have only one agent running in my domain, and it's only looking at about 4 domain controllers, so load should not be an issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Dec 2010 23:10:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4902#M3597</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2010-12-08T23:10:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4903#M3598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is there any mechanism for user identification over SSL VPN that utilizes the credentials provided by the user to make the VPN connection?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 21:36:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4903#M3598</guid>
      <dc:creator>kpatten</dc:creator>
      <dc:date>2010-12-09T21:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4904#M3599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;kpatten wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any mechanism for user identification over SSL VPN that utilizes the credentials provided by the user to make the VPN connection?&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know - I would have thought that would be the logical way of doing user dientification on the VPN link, but I'm not sure if it works that way or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe someone from Palo Alto can clarify for us?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Dec 2010 21:53:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4904#M3599</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2010-12-09T21:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4905#M3600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the SSL VPN login will populate the traffic, threat, url, etc. logs with User-ID information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Dec 2010 23:37:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4905#M3600</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-12-15T23:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4906#M3601</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;kbrazil wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the SSL VPN login will populate the traffic, threat, url, etc. logs with User-ID information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah, except it doesn't always- not for long-duration VPN connections (see original question in this thread).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPN users originally appear in the "from user" ID field - but if they stay logged on for a long enough period of time (seems to be about 80-90 minutes) the "from user' field becomes blank.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;doesn't really matter - I've worked around it for now - but it's a minor annoyance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Dec 2010 23:07:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4906#M3601</guid>
      <dc:creator>dagibbs</dc:creator>
      <dc:date>2010-12-19T23:07:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4907#M3602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would file a Support case as this does not seem to be expected behavior.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Dec 2010 01:17:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4907#M3602</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-12-20T01:17:25Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4908#M3603</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I get this behaviour and I suspect that the problem is from whose users that open vpn ssl sessions from same public IP. Normally, Palo Alto device recognises the last user login from that IP (at the begining recognises several users but only for 20 minutes).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know if Palo Alto has a way to map this users....maybe throught a session cookie?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 11:41:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4908#M3603</guid>
      <dc:creator>daniel_varela</dc:creator>
      <dc:date>2010-12-22T11:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4909#M3604</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The User-ID is being tied to the internal assigned IP address, so I'm not sure that the external IP address is the issue.&amp;nbsp; I suspect it may be a timing issue or conflict with the User-ID agent or Captive Portal logic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Dec 2010 17:31:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4909#M3604</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-12-22T17:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSL VPN and User identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4910#M3605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This happens not only with user-id or captive portal, it happens with local&lt;/P&gt;&lt;P&gt;users too. How can the PA map the whole session? If all the connections&lt;/P&gt;&lt;P&gt;uses the same public IP there is a problem, how can keep the information of&lt;/P&gt;&lt;P&gt;all users? It uses port number? Some kind of cookie? We've checked all&lt;/P&gt;&lt;P&gt;types of timeout and we didn't find anything.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Dec 2010 08:24:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ssl-vpn-and-user-identification/m-p/4910#M3605</guid>
      <dc:creator>daniel_varela</dc:creator>
      <dc:date>2010-12-23T08:24:00Z</dc:date>
    </item>
  </channel>
</rss>

