<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID for BYOD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184693#M56616</link>
    <description>&lt;P&gt;You can send IP-user-mappings to Palo Alto using XML API. I have never used Ruckus, so I&amp;nbsp;don't know how this can be implemented for their WLCs. Some Radius servers, like Aruba ClearPass, have builtin support for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/user-id/send-user-mappings-to-user-id-using-the-xml-api" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/user-id/send-user-mappings-to-user-id-using-the-xml-api&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 31 Oct 2017 11:38:51 GMT</pubDate>
    <dc:creator>TerjeLundbo</dc:creator>
    <dc:date>2017-10-31T11:38:51Z</dc:date>
    <item>
      <title>User-ID for BYOD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184508#M56580</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to search for information on how to capture User-ID for BYOD using Ruckus WLC but couldn'd find usefull info? Can anyone point me in the right direction?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;~sK&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 18:10:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184508#M56580</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-10-30T18:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for BYOD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184549#M56586</link>
      <description>&lt;P&gt;For BYOD, you can use captive portal to learn the mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Captive-Portal/tac-p/60461#M926" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Configure-Captive-Portal/tac-p/60461#M926&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 18:28:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184549#M56586</guid>
      <dc:creator>mgarg</dc:creator>
      <dc:date>2017-10-30T18:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for BYOD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184552#M56588</link>
      <description>&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am planning on using the Captive Portal as the second option; however, my plan is to use a wireless controller(Rukus) to monitor the syslog event logs and extract the usernames and IP addresses.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got a bit confused by the instructions in the link below as it says "Determine whether there is a pre-defined syslog filter for your particular syslog sender(s). Palo Alto Networks provides several pre-defined syslog filters, which are delivered as Application content updates and are therefore updated dynamically as new filters are developed. The pre-defined filters are global to the firewall, whereas manually defined filters apply to a single virtual system only."&amp;nbsp; We don't have a virtual system. Does that mean that I will not be able to create a manual filter for the WLC we have which is Rucks WLC if we don't have a virtual system?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/user-id-features/user-id-integration-with-syslog#_50964" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/user-id-features/user-id-integration-with-syslog#_50964&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best, ~zK&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2017 20:18:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184552#M56588</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-10-30T20:18:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for BYOD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184693#M56616</link>
      <description>&lt;P&gt;You can send IP-user-mappings to Palo Alto using XML API. I have never used Ruckus, so I&amp;nbsp;don't know how this can be implemented for their WLCs. Some Radius servers, like Aruba ClearPass, have builtin support for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/user-id/send-user-mappings-to-user-id-using-the-xml-api" target="_blank"&gt;https://www.paloaltonetworks.com/documentation/70/pan-os/pan-os/user-id/send-user-mappings-to-user-id-using-the-xml-api&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 11:38:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/184693#M56616</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2017-10-31T11:38:51Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for BYOD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/185794#M56797</link>
      <description>&lt;P&gt;Thanks!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2017 18:15:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/185794#M56797</guid>
      <dc:creator>Sadik_Khirbash</dc:creator>
      <dc:date>2017-11-07T18:15:11Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID for BYOD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/185918#M56813</link>
      <description>&lt;P&gt;I have a similar deployment, using a Cisco WLC with Cisco ISE. WLC authenticates on ISE (Radius) which uses a variety of identity sources (mainly an AD domain, but it also proxies Radius queries to external sources). ISE "Passed Authentication" logs are sent to a couple of Win 2012 VMs which run PAN User-ID agents and extract the IP-UserID pair, which is made available to 4 PA firewalls. I use two servers to have some delay between reboots (to update Windows and/or User-ID), because each reboot clears the mappings. The two User-ID servers also can poll domain controllers to further improve both detail and reliability of their data. Bonus: we have 802.1x implemented on our Cisco switches, so the whole thing works just the same for wired authentications.&lt;BR /&gt;&lt;BR /&gt;This way we have:&lt;BR /&gt;- UserID = user -&amp;gt; user is on a non-AD client&lt;/P&gt;&lt;P&gt;- UserID = user@somewhere -&amp;gt; user is authenticated on external source (radius proxy), and comes from "somewhere"&lt;/P&gt;&lt;P&gt;- UserID = domain\user -&amp;gt; user is on an AD client (rewritten from UserID = user when the AD client polls the domain, after 802.1x auth)&lt;BR /&gt;&lt;BR /&gt;Since every new authentication for an IP clears the database entry for the previous one, I've set the longest possible timeout for IP-user association (there's basically no option for users to access our network without authentication... ...hacking aside, of course, but that's out of the scope of this thread, and even of PA).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's all I can tell you, the whole thing works for us (&amp;gt;10k clients). Happy reg-ex'ing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; (I assume Ruckus does things differently from Cisco ISE/WLC, so no point giving you our expressions)&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2017 08:38:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-for-byod/m-p/185918#M56813</guid>
      <dc:creator>michelealbrigo</dc:creator>
      <dc:date>2017-11-08T08:38:31Z</dc:date>
    </item>
  </channel>
</rss>

