<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID WiFi and LAN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159773#M52162</link>
    <description>&lt;P&gt;Correct, internally, just use GP on internal gateway for user authent. No Tunnel, just authen.&lt;/P&gt;&lt;P&gt;And if you want to go farther, you can, in futur, use HIP for giving acces to dedicate ressources &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
    <pubDate>Tue, 06 Jun 2017 15:28:30 GMT</pubDate>
    <dc:creator>VinceM</dc:creator>
    <dc:date>2017-06-06T15:28:30Z</dc:date>
    <item>
      <title>User ID WiFi and LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159731#M52154</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our organisation&amp;nbsp;does not use 802.1x authentication in our environment. We have LAN and WiFi for our employees. We want to implement User ID with PA with AD domains and User ID Agent. However I could not find documentation on User ID behaviour in following scenario:&lt;/P&gt;&lt;P&gt;Our users have laptops and they use LAN when laptops are docked into docking stations. But when a user removes a laptop from docking station then he is immediately connected to WiFi and gets another IP. Again when he comes back to his place he will be connected with LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any documentation on how such situation is handled by user id and what are the best practices in such scenario?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;R&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:26:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159731#M52154</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2017-06-06T14:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: User ID WiFi and LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159742#M52155</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN class=""&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973" target="_self"&gt;rjdahav163&lt;/A&gt;,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;In this case, maybe you should have a look on deploying GP on all laptop and use GP on both external and internal gateway with transparent authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Switching from wire to wifi auth is really fast.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Ref:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/60/globalprotect/global_protect_6-0/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/globalprotect/global_protect_6-0/globalprotect-quick-configs/mixed-internal-and-external-gateway-configuration.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Hope help&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:41:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159742#M52155</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2017-06-06T14:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: User ID WiFi and LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159756#M52157</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/44973"&gt;@rjdahav163&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The computer already has an IP and a mapping on your wireless network, but the binding order makes it so that they are using the ethernet connection instead of the wireless connection. The mapping will simply have two IP addresses listed for that user. For example if my laptop is docked I'm mapped to say&amp;nbsp;&lt;STRONG&gt;10.*.*.*&lt;/STRONG&gt; but my wireless connection is listed as&amp;nbsp;&lt;STRONG&gt;172.16.*.*&lt;/STRONG&gt; then the firewall will show my user-id mapping to both 10.191.16.17 and 172.16.1.2 both at the same time, once my laptop is undocked then I simply see the users traffic move the source address to 172.16.1.2 but the mapping doesn't really change.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 14:56:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159756#M52157</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-06-06T14:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: User ID WiFi and LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159758#M52159</link>
      <description>&lt;P&gt;Thanks VinceM for your reply. So if I understand correctly, when internal network is detected GP will not initiate VPN right but only send the IP-Username association to the FW?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 15:10:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159758#M52159</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2017-06-06T15:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: User ID WiFi and LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159765#M52160</link>
      <description>&lt;P&gt;Thanks BPry for your reply. Your solution looks good.&amp;nbsp;Will try out and post a feedback.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 15:14:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159765#M52160</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2017-06-06T15:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: User ID WiFi and LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159766#M52161</link>
      <description>&lt;P&gt;I agree with BPry's solution, we currently have a similar setup in our environment and works just fine between LAN/WLAN.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 15:26:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159766#M52161</guid>
      <dc:creator>Nick.Chenault</dc:creator>
      <dc:date>2017-06-06T15:26:14Z</dc:date>
    </item>
    <item>
      <title>Re: User ID WiFi and LAN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159773#M52162</link>
      <description>&lt;P&gt;Correct, internally, just use GP on internal gateway for user authent. No Tunnel, just authen.&lt;/P&gt;&lt;P&gt;And if you want to go farther, you can, in futur, use HIP for giving acces to dedicate ressources &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jun 2017 15:28:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-wifi-and-lan/m-p/159773#M52162</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2017-06-06T15:28:30Z</dc:date>
    </item>
  </channel>
</rss>

