<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Agentless USER-ID - rules in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70908#M40616</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When you are lookigng at the logs, Click the maginifying glass on the far left and see if its picking up the username.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2016 17:00:57 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2016-01-14T17:00:57Z</dc:date>
    <item>
      <title>Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70896#M40611</link>
      <description>&lt;P&gt;Good Day&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm testing user-id in policy-rules and its not working the way I thought it would.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Example Rule&lt;/P&gt;
&lt;P&gt;src zone/ip - Zone A/any&lt;/P&gt;
&lt;P&gt;dst zone/ip - Zone B/any&lt;/P&gt;
&lt;P&gt;user - gdc\test.user&lt;/P&gt;
&lt;P&gt;application - any&lt;/P&gt;
&lt;P&gt;service - application-default&lt;/P&gt;
&lt;P&gt;action - allow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I start a ping to a server/workstation from Zone A to Zone B and I get request timeout, but if I remove the user the ping works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not how I thought it would work, I thought if I'm pinging from a workstation logged in as test.user that in the rule if I added the user it would ping throw, but it isn't.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you tell me why this is happening?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dana&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 14:43:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70896#M40611</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-14T14:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70899#M40612</link>
      <description>&lt;P&gt;have you validated that the firewall has a mapping of the IP to User?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you see a deny log showing the ICMP request with the source user the traffic is being generated from?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 15:01:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70899#M40612</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-01-14T15:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70900#M40613</link>
      <description>&lt;P&gt;Yes it connects to the AD brings back the userid mappings, and yes it is dropping the ICMP ping, but as I mentioned if I delete the user the ping works.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 15:04:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70900#M40613</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-14T15:04:31Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70908#M40616</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;When you are lookigng at the logs, Click the maginifying glass on the far left and see if its picking up the username.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 17:00:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70908#M40616</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2016-01-14T17:00:57Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70909#M40617</link>
      <description>&lt;P&gt;When you say "it brings back the user id mappings." &amp;nbsp;Does it actually provide the IP to User ID mapping for the source user in question?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the deny log, does the denied ICMP request show the source user ID that you're expecting?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should see something like this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ME@FIREWALLNAME(active)&amp;gt; show user ip-user-mapping(mp) ip&amp;nbsp;(USER IP 1.1.11)&lt;/P&gt;
&lt;P&gt;IP address: (USER IP 1.1.1.1) (vsys1)&lt;BR /&gt;User: (USER ID)&lt;BR /&gt;From: UIA&lt;BR /&gt;Idle Timeout: 3371s&lt;BR /&gt;Max. TTL: 3371s&lt;BR /&gt;Groups that the user belongs to (used in policy)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2016 17:13:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70909#M40617</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-01-14T17:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70986#M40642</link>
      <description>&lt;P&gt;Yes I get the correct user mapping. The rule is jump and go to the deny all rule a the bottom of the rules set... which is wierd, but if I set the User tab to "known-user" it works..... but not if I choose select and put in the group.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 16:18:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70986#M40642</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-15T16:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70988#M40644</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/35324"&gt;@burtond﻿&lt;/a&gt;&amp;nbsp;some screen shots might be helpful for us...Rule/Logs&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also if you're using a "group" in the rule do you have that group in the "Group Mapping?" In the user identifcation in the "Group Include List?"&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 16:28:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70988#M40644</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2016-01-15T16:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70989#M40645</link>
      <description>&lt;P&gt;Yes, I've even removed the User Identification setting commited and configured it again and still the same issue&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 16:35:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/70989#M40645</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-15T16:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71018#M40651</link>
      <description>&lt;P&gt;Networking&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2042i7EF6357026AABEE2/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Networking.jpg" title="Networking.jpg" /&gt;&lt;/P&gt;
&lt;P&gt;Groups&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2043i57F8278F7053FEF3/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Groups.jpg" title="Groups.jpg" width="468" height="307" /&gt;&lt;/P&gt;
&lt;P&gt;User Mappings&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2045iD92D7992E00A018E/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="User Mappings.png" title="User Mappings.png" width="593" height="334" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2046iD81960EF9C95113F/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="User.jpg" title="User.jpg" width="578" height="373" /&gt;&lt;/P&gt;
&lt;P&gt;All the groups&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2047iACA50483EAE56899/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="All Groups.png" title="All Groups.png" width="491" height="317" /&gt;&lt;/P&gt;
&lt;P&gt;Group Domain Users&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2048iD8EBAAA74D18FA3F/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Group Domain Users.png" title="Group Domain Users.png" width="428" height="191" /&gt;&lt;/P&gt;
&lt;P&gt;Rule that works&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2049iFB0431EF9E24C61E/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Rule that works.png" title="Rule that works.png" /&gt;&lt;/P&gt;
&lt;P&gt;Ping to Zone B&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2050i05FB970D4598F8C3/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Ping to Zone B.png" title="Ping to Zone B.png" width="458" height="232" /&gt;&lt;/P&gt;
&lt;P&gt;Ping Allowed&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2051i858B6FB0B8F07B1C/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Ping Allowed.png" title="Ping Allowed.png" width="687" height="121" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rule that doesn't work&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2052iB03A09E18BF57EEC/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Rule that doesn't work.png" title="Rule that doesn't work.png" /&gt;&lt;/P&gt;
&lt;P&gt;Ping to Zone B 2&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2053iC46767CFFFE4FA3C/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Ping to Zone B 2.png" title="Ping to Zone B 2.png" width="507" height="332" /&gt;&lt;/P&gt;
&lt;P&gt;Ping dropped&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2054i719E94DEC85ACB09/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Ping dropped.png" title="Ping dropped.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 19:58:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71018#M40651</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-15T19:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71073#M40667</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your group mapping, the users are mapped as 'zonea.ca\user' while in the user mapping, the user is 'zonea\user'&lt;/P&gt;
&lt;P&gt;This means the mapping information from the group is set to the FQDN while the uidagent collects the netbios domain&lt;/P&gt;
&lt;P&gt;this causes a mismatch when your security policy is set to a group&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you can resolve this issue by setting the group mapping user domain to the netbios version:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2073iB3BC960178BA6001/image-size/original?v=mpbl-1&amp;amp;px=-1" alt="2016-01-18_08-46-35.png" title="2016-01-18_08-46-35.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;once this is committed, refresh your group mapping&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug user-id reset group-mapping all&lt;BR /&gt;&amp;gt; debug user-id refresh group-mapping all&lt;/PRE&gt;
&lt;P&gt;afterward your users should start showing up in the group listing as zonea\user1 zonea\user2 etc&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;hope this helps&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 07:50:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71073#M40667</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-01-18T07:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71097#M40672</link>
      <description>&lt;P&gt;I'm running PAN-VM version 6.17 so the Group Mapping - Server Profile tab looks like this&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/2083i5731F8A1362DA005/image-size/original?v=mpbl-1&amp;amp;px=-1" border="0" alt="Group Mappings.png" title="Group Mappings.png" width="457" height="424" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 12:52:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71097#M40672</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-18T12:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71099#M40673</link>
      <description>&lt;P&gt;I found it, it is under the Server Profile - LDAP, thanks&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 12:55:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71099#M40673</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-18T12:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Agentless USER-ID - rules</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71101#M40675</link>
      <description>&lt;P&gt;Thanks Reaper, worked like a charm....very cool&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jan 2016 13:04:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/agentless-user-id-rules/m-p/71101#M40675</guid>
      <dc:creator>burtond</dc:creator>
      <dc:date>2016-01-18T13:04:26Z</dc:date>
    </item>
  </channel>
</rss>

