<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ignore all Computers from xmlapi mappings in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-all-computers-from-xmlapi-mappings/m-p/125706#M46453</link>
    <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I am trying to intergrate clearpass with Palo alto using xlampi, all was going well however i struck a problem&lt;/P&gt;&lt;P&gt;In clearpass i have two types of users that are autheticating, domain joined machines (which authenticate using "compute authentication" and i also have byod users that authenticate using user based ad authetication.&lt;/P&gt;&lt;P&gt;so when a byod users authenticates with his ad credentials against clear pass and this is passed through to Palo alto all is good . &amp;nbsp;Ihave a xlampi mapping of user and IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when a user authenticates against Clearpass as a domain machine ,I now have a xmlapi mapping of ip and computer name . and considering my palo alto policies are user based policies user cant get internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have uia in play which works well for domain machines, but i have the problem when both are in play sometimes the xmlapi mapping from clearpass overides the uia mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;My thought was to set a ignore list &amp;nbsp;as all computers that get authenticated via xmlapi appear domain\computername$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all | match $&lt;/P&gt;&lt;P&gt;it returns 1026 results so using set vsys vsys1 user-id-collector ignore-user domain\*$&amp;nbsp;&amp;nbsp;&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;however this brings all users back will ignore 1026&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and thats were i am stuck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Nov 2016 23:30:17 GMT</pubDate>
    <dc:creator>PaulBrock</dc:creator>
    <dc:date>2016-11-10T23:30:17Z</dc:date>
    <item>
      <title>Ignore all Computers from xmlapi mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-all-computers-from-xmlapi-mappings/m-p/125706#M46453</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I am trying to intergrate clearpass with Palo alto using xlampi, all was going well however i struck a problem&lt;/P&gt;&lt;P&gt;In clearpass i have two types of users that are autheticating, domain joined machines (which authenticate using "compute authentication" and i also have byod users that authenticate using user based ad authetication.&lt;/P&gt;&lt;P&gt;so when a byod users authenticates with his ad credentials against clear pass and this is passed through to Palo alto all is good . &amp;nbsp;Ihave a xlampi mapping of user and IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However when a user authenticates against Clearpass as a domain machine ,I now have a xmlapi mapping of ip and computer name . and considering my palo alto policies are user based policies user cant get internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have uia in play which works well for domain machines, but i have the problem when both are in play sometimes the xmlapi mapping from clearpass overides the uia mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that makes sense&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;My thought was to set a ignore list &amp;nbsp;as all computers that get authenticated via xmlapi appear domain\computername$&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user ip-user-mapping all | match $&lt;/P&gt;&lt;P&gt;it returns 1026 results so using set vsys vsys1 user-id-collector ignore-user domain\*$&amp;nbsp;&amp;nbsp;&amp;nbsp; ?&lt;/P&gt;&lt;P&gt;however this brings all users back will ignore 1026&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and thats were i am stuck.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Nov 2016 23:30:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-all-computers-from-xmlapi-mappings/m-p/125706#M46453</guid>
      <dc:creator>PaulBrock</dc:creator>
      <dc:date>2016-11-10T23:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore all Computers from xmlapi mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-all-computers-from-xmlapi-mappings/m-p/125772#M46458</link>
      <description>&lt;P&gt;Can you change the script which sends user info from Clearpass to PA? That would be the best point where to filter which info is sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2016 07:23:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-all-computers-from-xmlapi-mappings/m-p/125772#M46458</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-11-11T07:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Ignore all Computers from xmlapi mappings</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ignore-all-computers-from-xmlapi-mappings/m-p/195369#M58368</link>
      <description>&lt;P&gt;Do you have the following set?&lt;/P&gt;&lt;P&gt;CPPM &amp;gt; Administration &amp;gt; External Servers &amp;gt; Endpoint Context Servers &amp;gt; (Your PANs) &amp;gt; Username Transformation = Prefix NETBIOS name&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have users connecting with Computer Authentication and they show up as:&lt;/P&gt;&lt;P&gt;(domain)/(computer host name)$&amp;nbsp;&lt;/P&gt;&lt;P&gt;example:&amp;nbsp; abc/my-host$&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2018 19:55:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ignore-all-computers-from-xmlapi-mappings/m-p/195369#M58368</guid>
      <dc:creator>etnerual</dc:creator>
      <dc:date>2018-01-16T19:55:23Z</dc:date>
    </item>
  </channel>
</rss>

