<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: wrong user-id mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/171023#M54148</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;may be I didn't explain the problem clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;So, for example, the user logged in to the PC - after that paloalto had the&amp;nbsp;correct IP address. After that user opened any site in web browser, that used LDAP authentication. Then paloalto has IP address of the server, where that site was hosted, as an IP address mapped to the user. &amp;nbsp;So if security rule allows access by user-id, it will not match IP address of the user's PC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Aug 2017 14:52:14 GMT</pubDate>
    <dc:creator>ppk_vs</dc:creator>
    <dc:date>2017-08-10T14:52:14Z</dc:date>
    <item>
      <title>wrong user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/170973#M54138</link>
      <description>&lt;P&gt;&amp;nbsp;Hello everybody,&lt;/P&gt;&lt;P&gt;We have a problem with a user to IP&amp;nbsp;mapping. &amp;nbsp;Doesn't matter which version of PanOS - 7 or 8, doesn't matter if it's using windows agent or direct access from paloalto to LDAP servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;Let's say a user is going&amp;nbsp;to some server, windows exchange for example, and this server authenticates the user by LDAP. Then windows agent will have exchange's IP address mapped to the user name.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; For now, I have resolved this problem by excluding servers subnets in windows agent configuration. But not sure, may be there is a better way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vladimir.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 10:39:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/170973#M54138</guid>
      <dc:creator>ppk_vs</dc:creator>
      <dc:date>2017-08-10T10:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: wrong user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/171014#M54146</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/68826"&gt;@ppk_vs&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm not really seeing the issue. The way that user-id works is the user that is logged into the server, or the last to log in within the age-out, is the user mapped to that IP. So if you have someone log into your exchange server traffic do something really quick and then log out, they'll maintain the user-id mapping until another account logs a security event or the User ID timeout has been hit (if enabled).&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you don't want this action to take place then you would do exactly as you describe here, you exlude the IPs from user identification.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 13:46:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/171014#M54146</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-10T13:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: wrong user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/171023#M54148</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;may be I didn't explain the problem clear.&lt;/P&gt;&lt;P&gt;&amp;nbsp;So, for example, the user logged in to the PC - after that paloalto had the&amp;nbsp;correct IP address. After that user opened any site in web browser, that used LDAP authentication. Then paloalto has IP address of the server, where that site was hosted, as an IP address mapped to the user. &amp;nbsp;So if security rule allows access by user-id, it will not match IP address of the user's PC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Aug 2017 14:52:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/171023#M54148</guid>
      <dc:creator>ppk_vs</dc:creator>
      <dc:date>2017-08-10T14:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: wrong user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/389862#M90654</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever find a solution to your problem? I am having the same issue. what did you end up doing to to get the ip user mapping to the user's machine and not the authentication server?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 19:23:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/389862#M90654</guid>
      <dc:creator>Kolby_Baker</dc:creator>
      <dc:date>2021-03-08T19:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: wrong user-id mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/459216#M101976</link>
      <description>&lt;P&gt;Sorry, I have just seen the answer. So, I normally just use user-id exclusion lists for such server for which I don't want to use a user-id from the one side and where can some authentication event happen.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jan 2022 12:19:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/wrong-user-id-mapping/m-p/459216#M101976</guid>
      <dc:creator>ppk_vs</dc:creator>
      <dc:date>2022-01-18T12:19:35Z</dc:date>
    </item>
  </channel>
</rss>

