<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID mapping when host has 2 interfaces in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154393#M50878</link>
    <description>&lt;P&gt;the solution is to have your WLC or RADIUS server or whathaveyou to send syslog messages to the PA/UID Agent to map usernames with IPs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/user-id/configure-user-id-to-receive-user-mappings-from-a-syslog-sender.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/user-id/configure-user-id-to-receive-user-mappings-from-a-syslog-sender.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2017 14:09:47 GMT</pubDate>
    <dc:creator>bradk14</dc:creator>
    <dc:date>2017-04-27T14:09:47Z</dc:date>
    <item>
      <title>User-ID mapping when host has 2 interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154386#M50877</link>
      <description>&lt;P&gt;We've run into a problem which I understand, I'm just not sure how to fix. &amp;nbsp;A user on her laptop logs into the domain while her laptop is docked, so UIA has her ip address mapping to the wired connection. &amp;nbsp;Later, she undocks and flips over to wireless, but UIA no longer has a valid mapping for her since she AD still associates her wired IP address with her ID. &amp;nbsp;Once she redocks and starts accessing again with her wired IP, the original mapping is valid again and she is properly identified.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone encountered this and come up with a good resolution?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 14:06:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154386#M50877</guid>
      <dc:creator>craig.brooker</dc:creator>
      <dc:date>2017-04-27T14:06:21Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping when host has 2 interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154393#M50878</link>
      <description>&lt;P&gt;the solution is to have your WLC or RADIUS server or whathaveyou to send syslog messages to the PA/UID Agent to map usernames with IPs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/user-id/configure-user-id-to-receive-user-mappings-from-a-syslog-sender.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/61/pan-os/pan-os/user-id/configure-user-id-to-receive-user-mappings-from-a-syslog-sender.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 14:09:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154393#M50878</guid>
      <dc:creator>bradk14</dc:creator>
      <dc:date>2017-04-27T14:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping when host has 2 interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154685#M50935</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/58582"&gt;@bradk14&lt;/a&gt;&amp;nbsp;is right. &amp;nbsp;I've had this same problem in my environment&amp;nbsp;as well (&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Dual-NIC-IP-Mapping-Issue/m-p/5936#M4320" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Dual-NIC-IP-Mapping-Issue/m-p/5936#M4320&lt;/A&gt; )&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I opened a ticket with Microsoft and never could get to the bottom of it...Basically you're at the mercy of the randomness of the Windows OS and what NIC is used when authenticating to the DC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So really you've got 3 options.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First (probably Palo "recommended") - Use global protect&amp;nbsp;client. &amp;nbsp;While not necessarily ideal for everyone's environment&amp;nbsp;(adding another client to an image) it provides 100% accountability.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second - Do as Brad suggests and try adding the log source to your user ID environment. &amp;nbsp;This too might be overly burdensome especially if you have a lot of authentication&amp;nbsp;sources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Third - Leverage Captive Portal and hope for the best&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unfortunately your "cleanest" and most reliable solution will be GP.&lt;/P&gt;</description>
      <pubDate>Mon, 01 May 2017 14:02:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154685#M50935</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-05-01T14:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping when host has 2 interfaces</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154839#M50971</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks to both of you for the recommendations and background info. &amp;nbsp;Since we use ISE for wireless authentication&amp;nbsp;we're going to try syslog monitoring of it with a fallback to captive portal if needed.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 May 2017 13:20:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping-when-host-has-2-interfaces/m-p/154839#M50971</guid>
      <dc:creator>craig.brooker</dc:creator>
      <dc:date>2017-05-02T13:20:19Z</dc:date>
    </item>
  </channel>
</rss>

