<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: iSSUE Enabled UsedID agentless in Palo Alto in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168396#M53651</link>
    <description>&lt;DIV class="usertext-body may-blank-within md-container "&gt;&lt;DIV class="md"&gt;&lt;P&gt;Thank you all for your comments.&lt;BR /&gt;&lt;BR /&gt;But I would like to ask the process/query from workstation to FW and to AD?&lt;BR /&gt;This stages correct?&lt;BR /&gt;1. Workstation will generate userid to FW.&lt;BR /&gt;2. FW will check the policy based on UserID.&lt;BR /&gt;3. Then FW will query the AD then via LDAP to verify user acct.&lt;BR /&gt;4. if the reply from AD is confirmed, FW now will process the user request.&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Wed, 26 Jul 2017 13:02:02 GMT</pubDate>
    <dc:creator>searching1</dc:creator>
    <dc:date>2017-07-26T13:02:02Z</dc:date>
    <item>
      <title>iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168088#M53605</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We configured and using UsedID on our policy. 1 issue i've encountered is sometime PA can't resolve the UserID assigned for specific address. This happens only selective user and other user are fine.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Question are:&lt;/P&gt;&lt;P&gt;1. What would be the issue when PA can't resolve or just show unknown userid on logs?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. How to trouble and verify whether it's on workstation, FW or AD Server isssue?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;3. How to resolve this issue?&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 12:51:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168088#M53605</guid>
      <dc:creator>searching1</dc:creator>
      <dc:date>2017-07-25T12:51:58Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168093#M53607</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This might help:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-User-ID-Group-and-User-to-IP-Mapping/ta-p/59072" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Troubleshooting-User-ID-Group-and-User-to-IP-Mapping/ta-p/59072&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the&amp;nbsp;document attached to the article&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 13:14:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168093#M53607</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-25T13:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168242#M53633</link>
      <description>&lt;P&gt;Hey!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Run this command on the CMD of that machine - echo %logonserver%&lt;/P&gt;&lt;P&gt;2. Check if you have that DC added in the Server monitoring section.&lt;/P&gt;&lt;P&gt;3. If it's not there, add it. Issue resolved.&lt;/P&gt;&lt;P&gt;4. If it's there, check if there is an event log generated for that user's login.&lt;/P&gt;&lt;P&gt;5. Check useridd.log - less mp-log useridd.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Anurag&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jul 2017 21:24:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168242#M53633</guid>
      <dc:creator>ansharma</dc:creator>
      <dc:date>2017-07-25T21:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168396#M53651</link>
      <description>&lt;DIV class="usertext-body may-blank-within md-container "&gt;&lt;DIV class="md"&gt;&lt;P&gt;Thank you all for your comments.&lt;BR /&gt;&lt;BR /&gt;But I would like to ask the process/query from workstation to FW and to AD?&lt;BR /&gt;This stages correct?&lt;BR /&gt;1. Workstation will generate userid to FW.&lt;BR /&gt;2. FW will check the policy based on UserID.&lt;BR /&gt;3. Then FW will query the AD then via LDAP to verify user acct.&lt;BR /&gt;4. if the reply from AD is confirmed, FW now will process the user request.&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 26 Jul 2017 13:02:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168396#M53651</guid>
      <dc:creator>searching1</dc:creator>
      <dc:date>2017-07-26T13:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168411#M53654</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UserID-agent.PNG" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/10530iFF9FAE40E783A2D1/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="UserID-agent.PNG" alt="UserID-agent.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. Workstation will generate userid to FW -&amp;nbsp;Workstation will generate even/log entry on AD.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. FW will check the policy based on UserID - Yes, as well as other matching criteria.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Then FW will query the AD then via LDAP to verify user acct - Only for Group Mapping (agent will read LDAP tree), users logs are delivered by user-id agent (User Groups &amp;lt;-------&amp;gt; User ID &amp;lt;-------&amp;gt; IP address)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4. if the reply from AD is confirmed, FW now will process the user request - No, no direct connection/query for a particular user with AD. &amp;nbsp;All based on even/security&amp;nbsp;logs where user id agent has an account&amp;nbsp;on AD server with the&amp;nbsp;minimum permittion to read these logs.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 13:50:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168411#M53654</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-26T13:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168419#M53656</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/37163"&gt;@TranceforLife&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for sharing. In addition we are using agentless rightnow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just want to clarify&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;3. Only for Group Mapping (agent will read LDAP tree), users logs are delivered by user-id agent (User Groups &amp;lt;-------&amp;gt; User ID &amp;lt;-------&amp;gt; IP address).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- So this is only for w/ agent setup? How about agentlless setup? So Once the FW and AD has been setup via LDAP no more query will happen?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. &amp;nbsp;No, no direct connection/query for a particular user with AD. &amp;nbsp;All based on even/security&amp;nbsp;logs where user id agent has an account&amp;nbsp;on AD server with the&amp;nbsp;minimum permittion to read these logs.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;- So you mean Agentless or with agent doest query the AD anymore? All based on security logs (Generated on workstation?)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;sorry 3 &amp;amp; 4 part is not clear to me. apologize&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 14:21:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168419#M53656</guid>
      <dc:creator>searching1</dc:creator>
      <dc:date>2017-07-26T14:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168427#M53658</link>
      <description>&lt;P&gt;3) LDAP, in our case&amp;nbsp;,&amp;nbsp;is needed for Group Mapping query, user id info&amp;nbsp;still delivered by the&amp;nbsp;agents (FW or SW agent).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) User id agents (both FW and/or SW agent) talking to AD and then deliver security logs/events to FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is how l understood. Other advanced users can also comment and correct me if i am wrong.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 14:29:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168427#M53658</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-26T14:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168428#M53659</link>
      <description>&lt;P&gt;Thank you bro, Nice diagram, may i know where did you get that. bec. looking for docs regarding user ID process agentless/w/agent? cant find any good docs. always configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 14:32:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168428#M53659</guid>
      <dc:creator>searching1</dc:creator>
      <dc:date>2017-07-26T14:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: iSSUE Enabled UsedID agentless in Palo Alto</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168430#M53660</link>
      <description>&lt;P&gt;Say thanks to&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/36590"&gt;@acc6d0b3610eec313831f7900fdbd235&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;He did a very good job in providing some&amp;nbsp;nice free resources.&amp;nbsp;G&lt;SPAN&gt;et registered at a &lt;/SPAN&gt;learning&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;centre&lt;SPAN&gt;&amp;nbsp;and look&amp;nbsp;&lt;/SPAN&gt;for&lt;SPAN&gt;&amp;nbsp;:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Firewall Installation, Configuration, and Management: Essentials 1 (101) PAN-OS 7.0 Rev. B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;or&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Firewall 8.0 Essentials: Configuration and Management (EDU-110)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/Palo-Alto-Networks-Training-Resources-Available/m-p/76106" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/Palo-Alto-Networks-Training-Resources-Available/m-p/76106&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;p.s Snip was from one of the video training lessons&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jul 2017 14:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-enabled-usedid-agentless-in-palo-alto/m-p/168430#M53660</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-07-26T14:38:37Z</dc:date>
    </item>
  </channel>
</rss>

