<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How does the firewall work when they received unknown-user's packet? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-the-firewall-work-when-they-received-unknown-user-s/m-p/5684#M4163</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, rmonvon, It works. But it took more time (about 10 sec) than I've expected. :smileygrin:&lt;/P&gt;&lt;P&gt;Anyway It was very useful , Thanks Again. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Feb 2013 06:14:05 GMT</pubDate>
    <dc:creator>JTR</dc:creator>
    <dc:date>2013-02-04T06:14:05Z</dc:date>
    <item>
      <title>How does the firewall work when they received unknown-user's packet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-the-firewall-work-when-they-received-unknown-user-s/m-p/5682#M4161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, Guys. Nice to meet you.&lt;/P&gt;&lt;P&gt;I'm testing User-ID in PAN OS 4.1 and USER Agent 4.1.&lt;/P&gt;&lt;P&gt;There's something curious situation during my lab test.&lt;/P&gt;&lt;P&gt;I've deleted all ip-user-mapping information with 'clear user-cache all'.&lt;/P&gt;&lt;P&gt;So all users is unknown to firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5485_1.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the user agent still has ip-user mapping information using WMI probing.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5507_2.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case, I think the firewall should ask USER Agent&amp;nbsp; to get ip-user mapping information for the unknown user.&lt;/P&gt;&lt;P&gt;But the firewall can't get any information from the USER Agent, and the user still remains unknown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="3.jpg" class="jive-image-thumbnail jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/5508_3.jpg" width="450" /&gt;&lt;/P&gt;&lt;P&gt;and 'num of request of ip mapping msgs sent' doesn't increase.. only 'num of states msgs rcvd' and 'num of request of status msgs sent'&lt;/P&gt;&lt;P&gt;are increasing..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does any one know why does firewall work like this ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt; line-height: 1.5em;"&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 10:12:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-the-firewall-work-when-they-received-unknown-user-s/m-p/5682#M4161</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-02-01T10:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: How does the firewall work when they received unknown-user's packet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-the-firewall-work-when-they-received-unknown-user-s/m-p/5683#M4162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi...For unknown users and new connections, the PA would query the userID agent to see if there is a ip-user mapping.&amp;nbsp; Because you manually clear the user-cache and there may be existing sessions, the cache may be populated as unknown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I suggest you clear user-cache and also clear the session(s) via 'clear session all'.&amp;nbsp; Then generate new connection from that user IP to test.&amp;nbsp; Thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2013 18:46:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-the-firewall-work-when-they-received-unknown-user-s/m-p/5683#M4162</guid>
      <dc:creator>rmonvon</dc:creator>
      <dc:date>2013-02-01T18:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: How does the firewall work when they received unknown-user's packet?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-does-the-firewall-work-when-they-received-unknown-user-s/m-p/5684#M4163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, rmonvon, It works. But it took more time (about 10 sec) than I've expected. :smileygrin:&lt;/P&gt;&lt;P&gt;Anyway It was very useful , Thanks Again. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 06:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-does-the-firewall-work-when-they-received-unknown-user-s/m-p/5684#M4163</guid>
      <dc:creator>JTR</dc:creator>
      <dc:date>2013-02-04T06:14:05Z</dc:date>
    </item>
  </channel>
</rss>

