<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User-ID mapping in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190348#M57492</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You really shouldn't have any issues raising this value, the Citrix information should stay up-to-date and your thick clients will maintain their user-id information.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2017 14:02:41 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2017-12-06T14:02:41Z</dc:date>
    <item>
      <title>User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189791#M57402</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1512392827715.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12787i5090C20F3AA7D4A7/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="1512392827715.png" alt="1512392827715.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello. We have such kind of problem. This user has allowed privilege to visit this category and the other one, but PA very frequently identify it by ip, not the username (with User-ID). we use agentless client for mapping between PA and our AD.&lt;/P&gt;&lt;P&gt;The problem happens very often with a small amount of users (for example exactly with this one). Maybe some of you&amp;nbsp; have already faced with this?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 14:16:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189791#M57402</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2017-12-04T14:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189798#M57403</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76179"&gt;@AzerbaijanSupermarkets&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Could you send a screenshot of your User Mapping settings, specifically what your User Identification Timeout is set to. The biggest cause for this type of issue is inproper Log Monitor Frequency or having the User Identification Timeout set to low to actually keep the user mapped to the IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 14:21:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189798#M57403</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-04T14:21:48Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189825#M57409</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="print.jpg" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/12794i30D38CBB74355EE3/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="print.jpg" alt="print.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BPry,&lt;/P&gt;&lt;P&gt;you think that I should set this timeout higher than 45 minutes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 15:48:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189825#M57409</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2017-12-04T15:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189827#M57410</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/76179"&gt;@AzerbaijanSupermarkets&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Most definitively&amp;nbsp;this is what's causing your issue. If the user does not generate an authentication&amp;nbsp;event on the server within the 45 minute time period you are losing the mapping. Most office workers, esspecially on Windows, will not be generating any events on the AD server for the agent to read within a 45 minute time period.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 15:51:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189827#M57410</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-04T15:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189830#M57411</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I changed this time to 3 hours. Right now this problem happens only at one user. Hope this is going to help me.&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2017 16:26:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/189830#M57411</guid>
      <dc:creator>AzerbaijanSupermarkets</dc:creator>
      <dc:date>2017-12-04T16:26:04Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190066#M57433</link>
      <description>&lt;P&gt;Sorry for hijacking this thread, but I have been looking for a recommendation when it comes to user-id timeout value. We have a few thousand users logging in and out of Citrix throughout the day, but others work only locally on their laptops. We have user-id agents on all domain controllers and TS agents on all Citrix servers. In addition we have loads of users with BYOD devices on a wireless network where we get IP-user-mappings from the wireless controllers (Syslog events).&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 11:24:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190066#M57433</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2017-12-05T11:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190082#M57437</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The timeout value really depends on the enviroment. In an active enviroment where people will be generating logging events throughout the day, such as Citrix, the time can be set relatively low. When employees are working on one machine throughout the day I would generally set the timeout to equal your average work period, for example 480 mins for a total of an 8 hour ageout period.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing to really remember is that setting a higher ageout period could cause users to maintain the last user mapping longer than intended. In the majority of rulebases this wouldn't really be a big concern, but that would be dependant on what your configuration actually looks like.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2017 13:49:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190082#M57437</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-05T13:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190320#M57484</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_self"&gt;@BPry&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My worry is that by setting the timeout value low to keep user-id from Citrix updated we risk timing out users working on thick clients that do not generate security log events frequently. Would adding our Exchange servers to the userid agents help with that? Our desktop/laptop users generally have Outlook open all the time.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 12:23:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190320#M57484</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2017-12-06T12:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190345#M57489</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;What do you currently have your ageout value set to? You generally would not want to get any info from your Exchange servers.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 13:51:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190345#M57489</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-06T13:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190346#M57490</link>
      <description>&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480" target="_self"&gt;@BPry&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;45 minutes.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 13:58:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190346#M57490</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2017-12-06T13:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190348#M57492</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/53120"&gt;@TerjeLundbo&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;You really shouldn't have any issues raising this value, the Citrix information should stay up-to-date and your thick clients will maintain their user-id information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 14:02:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190348#M57492</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-12-06T14:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190354#M57496</link>
      <description>&lt;P&gt;I would recommend adding Exchange as another source for User-ID mapping.&amp;nbsp; Users may only login to the domain once in a day, but they check e-mail many times throughout the day.&amp;nbsp; Each time they open/use Outlook is another opportunity to refresh their user-to-ipaddress mapping.&amp;nbsp; With User-ID, more sources is a good thing(tm).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, what's your DHCP lease set to?&amp;nbsp; A good starting point for your user mapping timeout value is 1/2 the DHCP lease time.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2017 14:53:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190354#M57496</guid>
      <dc:creator>jvalentine</dc:creator>
      <dc:date>2017-12-06T14:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190827#M57586</link>
      <description>&lt;P&gt;For employee clients we use 8 days as DHCP lease time, so 4 days&amp;nbsp;user-ID timeout would perhaps be a bit excessive &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; But thanks for all the input, I'll probably increase the timeout to 4 hours as a start.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do others think about adding Exchange servers to the user-ID agents?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 14:05:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190827#M57586</guid>
      <dc:creator>TerjeLundbo</dc:creator>
      <dc:date>2017-12-08T14:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID mapping</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190873#M57592</link>
      <description>&lt;P&gt;A max timeout for user IP mapping is 24hrs so you don't need to worry about anything beyond that.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2017 19:19:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-mapping/m-p/190873#M57592</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2017-12-08T19:19:59Z</dc:date>
    </item>
  </channel>
</rss>

