<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to open SMB share (TSA user mapping issue) in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/139308#M48089</link>
    <description>&lt;P&gt;Is there any progress in this point? Maybe in a newer version of TSA? Am I the only one who thinks that his is a big problem? Is a workaround available for this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2017 13:34:21 GMT</pubDate>
    <dc:creator>Zencon</dc:creator>
    <dc:date>2017-01-25T13:34:21Z</dc:date>
    <item>
      <title>unable to open SMB share (TSA user mapping issue)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/89487#M43538</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Within a Poc with a PAN Firewall we ran into the following issue:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A terminal server (with TSA) in network a ist connected to a PAN Firewall. Fileserver in network b is also connected to the PAN Firewall.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Everything is configured properly and first testing are successfully done. (icmp, http). I were able to reach the Fileserver from the terminal server (both Windows Server 2012 R2). I could see in the logs the zones and the MS AD Users. Everything worked fine. But when I tried to open a smb share on the Fileserver it didn't work. (Windows Explorer: \\ip-address\c$) In the logs of the PAN I could see, that the traffic arrived on the Firewall, but no user was displayed. It seems that the TSA on the terminal server isn't mapping the user to ip (and port number). but only with this protocol.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;does anybody know anything about this issue and how to fix it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;best regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2016 09:53:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/89487#M43538</guid>
      <dc:creator>Zencon</dc:creator>
      <dc:date>2016-06-20T09:53:48Z</dc:date>
    </item>
    <item>
      <title>Re: unable to open SMB share (TSA user mapping issue)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/90237#M43557</link>
      <description>&lt;P&gt;Hi Christian&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mapped drives/fileshares run in a system context on windows server whereas http etc run in a user context. The operating system will only allow TSAgent to change source ports for services that run in a user context&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/TS-Agent-Unable-to-Map-Users-to-SMB-Traffic/ta-p/53106" target="_blank"&gt; TS Agent Unable to Map Users to SMB Traffic&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 07:10:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/90237#M43557</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-21T07:10:18Z</dc:date>
    </item>
    <item>
      <title>Re: unable to open SMB share (TSA user mapping issue)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/90273#M43560</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your answer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;just for clarification: There is no way to make TSA map those source ports as the service doesn't run in user context? So it's a problem for Microsoft to solve? It's hard to believe that this issue wasn't noticed before. SMB is a standard and I think many companies are using fileshares...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It's a pitty, but in this case the PAN Firewall would be completely useless for the customer, because removing the user filter from the policy will not be an option!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 08:16:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/90273#M43560</guid>
      <dc:creator>Zencon</dc:creator>
      <dc:date>2016-06-21T08:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: unable to open SMB share (TSA user mapping issue)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/90424#M43572</link>
      <description>&lt;P&gt;It's the way the operating system is designed and where it allows external services to plug into the stack&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's documented here: &lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/TS-Agent-Unable-to-Map-Users-to-SMB-Traffic/ta-p/53106" target="_blank"&gt;TS Agent Unable to Map Users to SMB Traffic&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2016 13:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/90424#M43572</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-06-21T13:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: unable to open SMB share (TSA user mapping issue)</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/139308#M48089</link>
      <description>&lt;P&gt;Is there any progress in this point? Maybe in a newer version of TSA? Am I the only one who thinks that his is a big problem? Is a workaround available for this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 13:34:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-open-smb-share-tsa-user-mapping-issue/m-p/139308#M48089</guid>
      <dc:creator>Zencon</dc:creator>
      <dc:date>2017-01-25T13:34:21Z</dc:date>
    </item>
  </channel>
</rss>

