<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189098#M57292</link>
    <description>&lt;P&gt;You can use the security log of you’re domain controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check device, User Identification. I prefer using the &lt;A href="https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/user-id-agent" target="_self"&gt;User ID Agent&lt;/A&gt; and point the Palo Alto to this agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are also scripts available to get the users from a radius log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2017 12:14:41 GMT</pubDate>
    <dc:creator>Sjoerd</dc:creator>
    <dc:date>2017-11-29T12:14:41Z</dc:date>
    <item>
      <title>User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189087#M57289</link>
      <description>&lt;P&gt;When enabling user-id where does it check against to get the information to identify&amp;nbsp; the users? I have it turned on for serveral zones and it only seems to work on the VPN user-id's.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 11:14:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189087#M57289</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-11-29T11:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189098#M57292</link>
      <description>&lt;P&gt;You can use the security log of you’re domain controllers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check device, User Identification. I prefer using the &lt;A href="https://www.paloaltonetworks.com/documentation/global/compatibility-matrix/user-id-agent" target="_self"&gt;User ID Agent&lt;/A&gt; and point the Palo Alto to this agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are also scripts available to get the users from a radius log.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 12:14:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189098#M57292</guid>
      <dc:creator>Sjoerd</dc:creator>
      <dc:date>2017-11-29T12:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189119#M57295</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This guide should be very helpful :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321" target="_blank"&gt;Getting Started User-ID&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers !&lt;/P&gt;
&lt;P&gt;-Kiwi.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 13:42:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189119#M57295</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2017-11-29T13:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189129#M57296</link>
      <description>&lt;P&gt;chances are that your user-id is not working at all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the user ID is only showing for GP connections as learned via authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 15:24:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189129#M57296</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-11-29T15:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189505#M57357</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;That is what I was thinking too Mick, we authenticate against LDAP instead of AD and I was wondering if the PA only does the userid against AD&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 13:28:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189505#M57357</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-01T13:28:59Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189506#M57358</link>
      <description>&lt;P&gt;i have never tried with LDAP but i'm sure its something to do with the PA being only able to read LDAP groups and not LDAP attributes that some LDAP admins use instead of groups.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;below is a link explaining this issue and a possible workaround.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it may not help you but at least give you a better understanding of whats going on.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Work-with-User-ID-and-OpenLDAP-Dynamic-Groups/ta-p/58811?attachment-id=505" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Learning-Articles/How-to-Work-with-User-ID-and-OpenLDAP-Dynamic-Groups/ta-p/58811?attachment-id=505&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 13:40:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189506#M57358</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-01T13:40:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189513#M57359</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;So the PA does do it userid queries only against AD&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 14:09:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189513#M57359</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-01T14:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189516#M57361</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are many methods to collect User id information: reading Active Directory authentication logs, server sessions (drive maps), API scripts, Captive portal, syslog collection, TerminalServer sessions, GlobalProtect authentication,...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please check out this article that highlights most of the main ways to collect user identification information and how to set it all up:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title=" Getting Started: User-ID" href="https://live.paloaltonetworks.com/t5/Featured-Articles/Getting-Started-User-ID/ta-p/69321" target="_blank"&gt; Getting Started: User-ID&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 15:04:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189516#M57361</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2017-12-01T15:04:53Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189518#M57362</link>
      <description>&lt;P&gt;well i have only briefly browsed the document but my assumptions are as follows.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your PA identifies its users via authentication, such as your VPN then you can use LDAP groups against those users for policies etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the previous link explains how to do this. but...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if your users do not auth via AD then you will not be able to map IP's to users as the LDAP server will not hold a database of user related IP's.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The PA user-id reads the security log on AD as this records users addresses when they use domain services, email, logon etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I would say yes to your previous post.. But.. (again)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the user-AD agent installed seperately has config settings for EDirectory.. as wll as AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mick.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;oops! someone has just posted previous to me so may be of better use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 15:09:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189518#M57362</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-01T15:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189519#M57363</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;&amp;nbsp;&amp;amp; &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the document I refer to is the one i posted earlier, not the one from &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/7608"&gt;@reaper&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry for the confusion....&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 15:11:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189519#M57363</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-01T15:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189530#M57368</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Also check to make sure that the User-ID is enabled on the zone. Its burned me a few times over the years.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 696px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12705i4DB481050A7919B7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2017 17:11:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189530#M57368</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2017-12-01T17:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189772#M57399</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes i got the one you sent thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 13:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/189772#M57399</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-04T13:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190146#M57453</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/11943"&gt;@kiwi&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Do you have to have a certain version of the userid agent for different OS's of the PA? I don't want to have to upgrage the agents every other month unless it does it automagically&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 17:45:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190146#M57453</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-05T17:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190160#M57455</link>
      <description>&lt;P&gt;No, i have used same agent for all 7.x versions, only had to upgrade when moved to v8. As requires a device cert.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;however v8 had other issues so rolled back to v7 and original agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have 2 agents so upgrading (if required) can be pretty seemless.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 18:32:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190160#M57455</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2017-12-05T18:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190165#M57459</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;good to know thanks for the info&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 19:09:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190165#M57459</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-05T19:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190196#M57461</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it is enabled on the zones but apparently I don't have everything it needs set up because its still not working. I can see how that would be annoying LOL &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 21:52:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/190196#M57461</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-05T21:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192089#M57756</link>
      <description>&lt;P&gt;I see that there is a userid agent method and a clientless userid method. What are people using the most? I know that the clientless method will cause more load on my firewall but i am not sure how to gage how much it will add. Also we do mostly LDAP on a unbuntu box all I saw was what looked like one compatible with active directory and window&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2017 15:58:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192089#M57756</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-18T15:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192482#M57808</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I have read over this a couple times and this is no small udertaking, we have a mix of authentication methods active directory, ad-ldap, open ldap and radius. I may try puttin the agent on the AD domain controller and see how much info I get from that. Unfortunately alot of the users are not a part of our domain since they are college student and connect using their own devices&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 16:14:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192482#M57808</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-20T16:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192487#M57811</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/18719"&gt;@jdprovine&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Do you seperate your students into a 'student' VLAN? It's possible to simply include IP ranges that you would actually expect to see the user-id information, and you could simply ignore your student BYOD devices.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 16:27:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192487#M57811</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-20T16:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192489#M57812</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Yes we do separate them into their own vlans as well as a separate zone on the PA.&amp;nbsp; A majority of our students use wireless for everything and we authenticate against radius to let them on the wireless(we have more than one wireless). Is it possible to get userid information from Radius?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Dec 2017 16:33:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id/m-p/192489#M57812</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2017-12-20T16:33:44Z</dc:date>
    </item>
  </channel>
</rss>

