<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: user-identification for VLAN Traffic in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6005#M4370</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All sorted out.&amp;nbsp; It had no issues with NAT or Routing rules ( was very confusing looking into specially when you 68 NAT rules).&amp;nbsp; What all I did was adding the 172.X.X.X network in the Allow List of the User-ID agent and creating a new sub-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your concern.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Feb 2012 10:41:30 GMT</pubDate>
    <dc:creator>kalyanram.piratla</dc:creator>
    <dc:date>2012-02-02T10:41:30Z</dc:date>
    <item>
      <title>user-identification for VLAN Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6001#M4366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Hi Guys,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;I am just wondering if any one could help me out on this as I am slightly lost creating and troubleshooting for the following issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt;It has been noticed that not all traffic had a user-id and it seems that any traffic originating from a VLAN goes down as “unknown” user.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt;So my question is, how can we make the PAN aware of the VLANS so that we can see if the change makes the users visible rather than remaining as unknown.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal"&gt;&lt;SPAN style="color: #0000ff;"&gt;Hope this information helps.&amp;nbsp; Looking forward to hear from you guys.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Many Thanks...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;Kal&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 15:16:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6001#M4366</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-01-23T15:16:46Z</dc:date>
    </item>
    <item>
      <title>Re: user-identification for VLAN Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6002#M4367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add to this, traffic originating from 172.22.10.0/24 network on a vlan has no access to the internet as well.&amp;nbsp; Looking at the traffic logs, it shows application as "incomplete".&amp;nbsp; As far as I understand, incomplete traffic is when the 3-way handshake is not completed.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What has to be done to enable the completion of the 3-hand shake?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Kal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 15:20:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6002#M4367</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-01-23T15:20:15Z</dc:date>
    </item>
    <item>
      <title>Re: user-identification for VLAN Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6003#M4368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For Issue#1;&lt;/P&gt;&lt;P&gt;Please check "user identification" is enabled on the zones which are associated to those VLANs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Issue#2;&lt;/P&gt;&lt;P&gt;You need to check Routing and NAT rules to make sure whether it is done properly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If config on either issues looks fine, you can contact support.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 04:47:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6003#M4368</guid>
      <dc:creator>snisar</dc:creator>
      <dc:date>2012-01-24T04:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: user-identification for VLAN Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6004#M4369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Snisar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information.&amp;nbsp; User-Identification has been checked for all the required zones.&amp;nbsp; I think there is something wrong the way I have configured the NAT and Security rule.&amp;nbsp; Will look into it shortly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be looking into changing the route and NAT policy that is in place.&amp;nbsp; What is confusing me is would this require configuring a Layer 2 network again for any specific physical interface?&amp;nbsp; I was thinking on this because, I have gone through a document which helps configuring a Layer 2 to Layer 3 on the PAN Device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;P&gt;Kal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2012 09:34:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6004#M4369</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-01-24T09:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: user-identification for VLAN Traffic</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6005#M4370</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;All sorted out.&amp;nbsp; It had no issues with NAT or Routing rules ( was very confusing looking into specially when you 68 NAT rules).&amp;nbsp; What all I did was adding the 172.X.X.X network in the Allow List of the User-ID agent and creating a new sub-interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your concern.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Feb 2012 10:41:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-identification-for-vlan-traffic/m-p/6005#M4370</guid>
      <dc:creator>kalyanram.piratla</dc:creator>
      <dc:date>2012-02-02T10:41:30Z</dc:date>
    </item>
  </channel>
</rss>

