<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy with user ID don't work in palo alto networks in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178950#M55609</link>
    <description>&lt;P&gt;hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the identification is enable on your zones ?&lt;/P&gt;&lt;P&gt;DEvice&amp;gt;network&amp;gt;zone&amp;gt; check the box "enable identification" in zone parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 27 Sep 2017 13:09:31 GMT</pubDate>
    <dc:creator>alle</dc:creator>
    <dc:date>2017-09-27T13:09:31Z</dc:date>
    <item>
      <title>Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178916#M55606</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured the users in the office to be identify with Active Directory. I can see the users identification in the Monitor tab. But when i set a rule with user AD identifier don't work!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I add two rules :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;rule 1: deny access for a specific AD users to social networks&lt;/P&gt;&lt;P&gt;rule 2: allow access to any users&amp;nbsp; (internet access).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The first rulee always don't take effect . I saw the users always access to all sites with the second rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is any suggestion please .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 09:57:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178916#M55606</guid>
      <dc:creator>ra7oub4</dc:creator>
      <dc:date>2017-09-27T09:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178941#M55608</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/73583"&gt;@ra7oub4&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you add more details about&amp;nbsp;how the rules are configured and how the firewall is logging the actual sessions ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 11:35:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178941#M55608</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-09-27T11:35:43Z</dc:date>
    </item>
    <item>
      <title>Re: Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178950#M55609</link>
      <description>&lt;P&gt;hello ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the identification is enable on your zones ?&lt;/P&gt;&lt;P&gt;DEvice&amp;gt;network&amp;gt;zone&amp;gt; check the box "enable identification" in zone parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 13:09:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178950#M55609</guid>
      <dc:creator>alle</dc:creator>
      <dc:date>2017-09-27T13:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178962#M55615</link>
      <description>&lt;P&gt;Click on mag glass and see what is session end reason.&lt;/P&gt;&lt;P&gt;Also go to URL filter log and see what action is for those users accessing unwanted sites.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 13:55:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178962#M55615</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-27T13:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178964#M55616</link>
      <description>&lt;P&gt;from CLI.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group list&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;copy the fqdn for the restricted group.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;show user group name "paste fqdn"&amp;nbsp;&amp;nbsp; (use quotes if fqdn has spaces)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;scroll down to ensure users are in that group and ensue domain\ is same as username in policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 14:20:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178964#M55616</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-27T14:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178965#M55617</link>
      <description>&lt;P&gt;To identify user's group membership it is easier to use following command:&lt;/P&gt;&lt;P&gt;&amp;gt; show user user-ids match-user raido&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 14:23:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178965#M55617</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2017-09-27T14:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178967#M55618</link>
      <description>&lt;P&gt;Noted...&amp;nbsp;&amp;nbsp;&amp;nbsp; thankyou.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2017 14:28:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/178967#M55618</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-09-27T14:28:56Z</dc:date>
    </item>
    <item>
      <title>Re: Policy with user ID don't work in palo alto networks</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/179189#M55649</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is solved .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for all your response.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2017 15:26:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/policy-with-user-id-don-t-work-in-palo-alto-networks/m-p/179189#M55649</guid>
      <dc:creator>ra7oub4</dc:creator>
      <dc:date>2017-09-28T15:26:49Z</dc:date>
    </item>
  </channel>
</rss>

