<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: The FW Can not match User based Rule when users were changed IP in using GP internal Gateway. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/188095#M57139</link>
    <description>&lt;P&gt;Yes, I have.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2017 01:20:31 GMT</pubDate>
    <dc:creator>KiCheonLee</dc:creator>
    <dc:date>2017-11-21T01:20:31Z</dc:date>
    <item>
      <title>The FW Can not match User based Rule when users were changed IP in using GP internal Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186096#M56847</link>
      <description>&lt;P&gt;My customer uses GP Internal Gateway with a non-Tunnel mode.&lt;/P&gt;&lt;P&gt;It means it uses just only user authentication and enforces user-based rules.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am facing an issue .&lt;/P&gt;&lt;P&gt;A user was connected to GP Internal&amp;nbsp; GW in office 1F and successed authentication.&lt;/P&gt;&lt;P&gt;The FW was updated A user has 192.168.1.1 from GP.&lt;/P&gt;&lt;P&gt;The user moves to 2F and changed IP from 192.168.1.1 to 192.168.2.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The user still reaches Internal GW but the FW still hold A user has 192.168.1.1 .&lt;/P&gt;&lt;P&gt;Therefore,&amp;nbsp; The user can't be enforced by his user based rules.&lt;/P&gt;&lt;P&gt;Finally, the user's traffics were blocked by the latest rule as any any block.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am expecting there would be two ways that could resolve the issue.&lt;/P&gt;&lt;P&gt;One,&amp;nbsp; If GP Agent could update changed IP to the FW, this issue would be resolved.&lt;/P&gt;&lt;P&gt;But I am expecting that could not update because using non-tunnel mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have another way of updating changed IP to the FW?&lt;/P&gt;&lt;P&gt;If you have, Please let me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another way, If GP could disconnect when it senses ip changed, this issue would be also resolved.&lt;/P&gt;&lt;P&gt;Because users must do authentication again and the GP agent will update IP-User mapping information to the FW.&lt;/P&gt;&lt;P&gt;Do you have another way of disconnecting GP when PC is changed another IP?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you have, Please let me know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And do you have other ways else? please let me know.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It would make me helpful.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;KC Lee&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 05:06:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186096#M56847</guid>
      <dc:creator>KiCheonLee</dc:creator>
      <dc:date>2017-11-09T05:06:03Z</dc:date>
    </item>
    <item>
      <title>Re: The FW Can not match User based Rule when users were changed IP in using GP internal Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186142#M56852</link>
      <description>&lt;P&gt;are you using AD for user mapping.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2017 08:48:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186142#M56852</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-09T08:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: The FW Can not match User based Rule when users were changed IP in using GP internal Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186437#M56871</link>
      <description>&lt;P&gt;No, we are not using.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 08:21:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186437#M56871</guid>
      <dc:creator>KiCheonLee</dc:creator>
      <dc:date>2017-11-10T08:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: The FW Can not match User based Rule when users were changed IP in using GP internal Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186513#M56886</link>
      <description>&lt;P&gt;Do you have user id enabled on the required zones.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 19:39:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/186513#M56886</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-10T19:39:00Z</dc:date>
    </item>
    <item>
      <title>Re: The FW Can not match User based Rule when users were changed IP in using GP internal Gateway.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/188095#M57139</link>
      <description>&lt;P&gt;Yes, I have.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2017 01:20:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/the-fw-can-not-match-user-based-rule-when-users-were-changed-ip/m-p/188095#M57139</guid>
      <dc:creator>KiCheonLee</dc:creator>
      <dc:date>2017-11-21T01:20:31Z</dc:date>
    </item>
  </channel>
</rss>

