<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID sometimes missing ntlmdomain\ on the firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6608#M4828</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found this..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;53258—Authenticating access to a file share folder hosted outside of the Active Directory domain was causing the firewall to change the User-IP Mapping to the username and password used to authenticate to the file share folder hosted outside of the Active Directory domain, instead of the Active Directory username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Resolved in 5.0.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'll be giving that a try!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Apr 2014 10:46:31 GMT</pubDate>
    <dc:creator>Dpeters1</dc:creator>
    <dc:date>2014-04-16T10:46:31Z</dc:date>
    <item>
      <title>User-ID sometimes missing ntlmdomain\ on the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6604#M4824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've recently seen this a couple of times on completely separate firewalls / AD infrastructures (a 2050 cluster and a 3020 cluster, both running 5.0.8). User ID is setup and working fine along with LDAP group mapping&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However on the odd occasion users report applications or URL categories blocked that should be allowed. It often "goes away" again soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I spotted in the URL and Traffic logs, the user is (for short periods) identified just as USERNAME, rather than DOMAIN\USERNAME...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This of course does not match rules with usernames specified in them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas why it may drop the domain name occasionally?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dave&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2014 11:38:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6604#M4824</guid>
      <dc:creator>Dpeters1</dc:creator>
      <dc:date>2014-04-11T11:38:59Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID sometimes missing ntlmdomain\ on the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6605#M4825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dave,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P data-angle="0" data-canvas-width="39.97612329483032" data-font-name="Helvetica" dir="ltr" style="font-size: 14.3284px; font-family: sans-serif;"&gt;This could be a known issue. Fixed 5.0.7, bug id &lt;SPAN class="selected highlight"&gt;52383.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-5734"&gt;PAN-OS 5.0.7: Addressed Issues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;5.0.7 has software buffer issues and hence upgrade to this version is not recommended, 5.0.10 is a stable version comparatively.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deepak&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Apr 2014 17:52:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6605#M4825</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2014-04-11T17:52:10Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID sometimes missing ntlmdomain\ on the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6606#M4826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you know if those PCs from where the usernames appear without the domain are perhaps running some sort of service in the background that is only associated with the username (and is missing the domain). Do you see logon event on the AD / DC security events with just the username? What is the user-ip-mapping on the UserID agent when you see the logs on the firewall show only the username?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 12 Apr 2014 22:37:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6606#M4826</guid>
      <dc:creator>sjamaluddin</dc:creator>
      <dc:date>2014-04-12T22:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID sometimes missing ntlmdomain\ on the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6607#M4827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that... I might be reading it wrong but doesn't it say that was addresses/fixed in 5.0.7 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless it wasn't rolled into 5.0.8 for some reason...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does look very similar though. I'll give a later build of 5.0.x a whirl today and see what happens!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2014 10:32:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6607#M4827</guid>
      <dc:creator>Dpeters1</dc:creator>
      <dc:date>2014-04-16T10:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID sometimes missing ntlmdomain\ on the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6608#M4828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Found this..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;53258—Authenticating access to a file share folder hosted outside of the Active Directory domain was causing the firewall to change the User-IP Mapping to the username and password used to authenticate to the file share folder hosted outside of the Active Directory domain, instead of the Active Directory username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Resolved in 5.0.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I'll be giving that a try!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2014 10:46:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6608#M4828</guid>
      <dc:creator>Dpeters1</dc:creator>
      <dc:date>2014-04-16T10:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID sometimes missing ntlmdomain\ on the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6609#M4829</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The fix in 5.0.7 is good for the succeeding maintenance release too, my recommendation of not moving to 5.0.7 is due to a software pool depletion issue that you might run into 5.0.7.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Apr 2014 15:40:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6609#M4829</guid>
      <dc:creator>dpalani</dc:creator>
      <dc:date>2014-04-16T15:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID sometimes missing ntlmdomain\ on the firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6610#M4830</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;Is this a multi domain environment and do you have server session read enabled?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif; color: #3b3b3b;"&gt;For multiple domain environments the data gathered from open sessions may not be accurate. This method does not deliver domain data with the user name and it is assumed that the user is a member of the domain that the monitored server is part of.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 May 2014 04:11:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-sometimes-missing-ntlmdomain-on-the-firewall/m-p/6610#M4830</guid>
      <dc:creator>dmaynard</dc:creator>
      <dc:date>2014-05-22T04:11:40Z</dc:date>
    </item>
  </channel>
</rss>

