<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Direct Access - is user Identification possible? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/68244#M39839</link>
    <description>&lt;P&gt;We have the same issue.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Nov 2015 20:21:16 GMT</pubDate>
    <dc:creator>LCMember4540</dc:creator>
    <dc:date>2015-11-16T20:21:16Z</dc:date>
    <item>
      <title>Microsoft Direct Access - is user Identification possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/4811#M3545</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have user identification working nicely using user ID agents on a few of our active directory domain members.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been looking at &lt;STRONG&gt;MS Direct Access&lt;/STRONG&gt; (and formerly UAG) and it seems that a DA implementation would show all connected users as having the same source IP address and therefore user ID. (The private IP address of the DA server.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do PA firewalls have a way of identifying which user the traffic inside the DA 'tunnel' is from?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess what I'm probably asking for is a 'DA Server User Agent' in the same way that there is a MS Terminal Server Agent which does a similar job.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jan 2013 09:36:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/4811#M3545</guid>
      <dc:creator>LCMember3410</dc:creator>
      <dc:date>2013-01-31T09:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access - is user Identification possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/4812#M3546</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bump on this. Thanks for asking this, Matt. We are looking for the same answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 18:54:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/4812#M3546</guid>
      <dc:creator>gwhyte</dc:creator>
      <dc:date>2013-10-31T18:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access - is user Identification possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/4813#M3547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just testing Direct Access and having the exact same issue - any updates? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 May 2014 11:36:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/4813#M3547</guid>
      <dc:creator>james.pyatt</dc:creator>
      <dc:date>2014-05-19T11:36:27Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access - is user Identification possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/68244#M39839</link>
      <description>&lt;P&gt;We have the same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2015 20:21:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/68244#M39839</guid>
      <dc:creator>LCMember4540</dc:creator>
      <dc:date>2015-11-16T20:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access - is user Identification possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/338980#M85188</link>
      <description>&lt;P&gt;same problem - any news on this?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 14:23:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/338980#M85188</guid>
      <dc:creator>TSchworer</dc:creator>
      <dc:date>2020-07-16T14:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access - is user Identification possible?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/339226#M85216</link>
      <description>&lt;P&gt;I'm thinking that you might try to monitor it before it gets to the DA server.&amp;nbsp; There should be a way to map the user public IP address to their user-id, e.g. if there are logs somewhere in either: DA server, AD, some other security tool, or similar, you could push that into user-id.&amp;nbsp; Not simple or elegant though.&amp;nbsp; I wouldn't try to monitor the traffic within the tunnel directly, but anything traversing your firewall going to the IP address of the DA server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 14:52:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/microsoft-direct-access-is-user-identification-possible/m-p/339226#M85216</guid>
      <dc:creator>nbutter</dc:creator>
      <dc:date>2020-07-17T14:52:44Z</dc:date>
    </item>
  </channel>
</rss>

