<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ip mapping with only Global Protect in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-ip-mapping-with-only-global-protect/m-p/49687#M36597</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm interresting in for this kind&amp;nbsp; surrogate identication. I would like to know if paloalto does something on this topic&lt;/P&gt;&lt;P&gt;regard's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Nov 2013 10:13:42 GMT</pubDate>
    <dc:creator>Gregoux</dc:creator>
    <dc:date>2013-11-05T10:13:42Z</dc:date>
    <item>
      <title>User ip mapping with only Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-ip-mapping-with-only-global-protect/m-p/49686#M36596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have a question regarding user ip mapping when only using Global Protect to authenticate users.&lt;/P&gt;&lt;P&gt;Without enabling any user-id agent. Neither external on a server, neither on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works as Global Protect identifies the logged-on user and uses this information to notify the firewall to place an user-ip mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I have tested the follow scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User A is logged on onto the network with ip x.x.x.x and authenticated by Global Protect.&lt;/P&gt;&lt;P&gt;He pulls out the network cable, as on that moment user B connects to the same network with the same ip x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User B has takeover the rights of user A.&lt;/P&gt;&lt;P&gt;This looks like a major securitybug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why doesn't Global Protect sets up a concurrent SSL connection to the Portal with a heartbeat, so the Firewall is sure that user A is still the same user?&lt;/P&gt;&lt;P&gt;When the SSL connection is broken, the firewall could remove the user-ip mapping.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is kind the way Juniper IC works, but obviously Palo Alto doesn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an other secure way to maintain user-ip mapping and to be sure there could not be any takover of ip addresses without the use of Active Directory Log reading with an user-id agent (so only with Global Protect)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Aug 2013 12:00:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-ip-mapping-with-only-global-protect/m-p/49686#M36596</guid>
      <dc:creator>robinheylen</dc:creator>
      <dc:date>2013-08-29T12:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: User ip mapping with only Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-ip-mapping-with-only-global-protect/m-p/49687#M36597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm interresting in for this kind&amp;nbsp; surrogate identication. I would like to know if paloalto does something on this topic&lt;/P&gt;&lt;P&gt;regard's&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 10:13:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-ip-mapping-with-only-global-protect/m-p/49687#M36597</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-11-05T10:13:42Z</dc:date>
    </item>
    <item>
      <title>Re: User ip mapping with only Global Protect</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-ip-mapping-with-only-global-protect/m-p/49688#M36598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi did you have a look to this documentation:&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://live.paloaltonetworks.com/docs/DOC-4820"&gt;https://live.paloaltonetworks.com/docs/DOC-4820&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this explain you how to modify the ttl for the idle session. if you decrease that it could be minimize the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Nov 2013 10:24:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-ip-mapping-with-only-global-protect/m-p/49688#M36598</guid>
      <dc:creator>Gregoux</dc:creator>
      <dc:date>2013-11-05T10:24:58Z</dc:date>
    </item>
  </channel>
</rss>

