<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Terminal server user identification in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206296#M60544</link>
    <description>&lt;P&gt;well ... ping is a system service .... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Mar 2018 11:11:45 GMT</pubDate>
    <dc:creator>reaper</dc:creator>
    <dc:date>2018-03-19T11:11:45Z</dc:date>
    <item>
      <title>Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/205046#M60241</link>
      <description>Hello.We have terminal server in which there are many users logged in.But we see them in traffic monitoring only as one Ip address and no separate users.I have installed terminal service agent on terminal server and everything is ok.IT shows connected and green and TS agent define the users.But in firewall i cant see the separate users in monitoring -traffic log. i want to mention that i use agentless ldap integration.But can check with user id agent also.Is there any tips regarding terminal server?</description>
      <pubDate>Tue, 13 Mar 2018 09:56:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/205046#M60241</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-03-13T09:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/205350#M60295</link>
      <description>&lt;P&gt;any ideas&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 09:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/205350#M60295</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-03-14T09:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/205608#M60350</link>
      <description>&lt;P&gt;hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;so if I understand correctly, the TSAgent is showing you all the users correctly?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I saw this once before where a &amp;lt;Well known AV vendor&amp;gt; webfiltering client was also installed on the terminal server.&lt;/P&gt;
&lt;P&gt;It intercepted all connections and proxied them locally, which caused the port mapping provided by the TSAgent to stop working (TSAgent also intercepts connections and changes the source port so the firewall knows which connections belong to a certain user)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If something similar is installed on your terminal server, you may need to deactivate the url filrtering, or disable the proxying&lt;/P&gt;</description>
      <pubDate>Thu, 15 Mar 2018 10:31:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/205608#M60350</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-15T10:31:57Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206136#M60510</link>
      <description>&lt;P&gt;Issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File shares set up by users on the terminal server are not identified by the TS Agent and are not mapped to a user in the traffic log.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Resolution:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the traffic is initiated by an application running with the context of a user (e.g. telnet), the socket information can be intercepted by the TS Agent which will replace the source port. However, if the traffic is generated by a service running with System context, the agent is not able to determine the user information. The TS-Agent will not identify SMB traffic a this is run in a system context.&lt;BR /&gt;The System Source Port Allocation Range and System Reserved Source Ports fields specify the range of ports that will be allocated to non-user sessions. Make sure the values specified in these fields do not overlap with the ports you designate for user traffic. These values can only be changed by editing the corresponding Windows registry settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have read this in the Internet.How one can handle with it?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 10:00:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206136#M60510</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-03-17T10:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206150#M60513</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70049"&gt;@Radmin_85&lt;/a&gt;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have read this in the Internet.How one can handle with it?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Not the answer you want to hear, but there is no solution. For SMB and other connections in system context you will not have user-ip-port mappings. If you really want to restrict connections from terminalservers to user connections you have to deny these connections (except the ones that that are required like SMB to Domaincontroller, Profileshares, ...) somewhere (on other external firewalls or with the local firewall.&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 17:28:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206150#M60513</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-17T17:28:02Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206234#M60528</link>
      <description>&lt;P&gt;But how about internet traffic&lt;/P&gt;&lt;P&gt;Is it possible to identify separate users who go to Internet&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 06:58:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206234#M60528</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-03-19T06:58:27Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206255#M60531</link>
      <description>&lt;P&gt;This definately is possible. What output does the following command show you: "show user ip-port-user-mapping all"?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 08:22:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206255#M60531</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-03-19T08:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206284#M60540</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 800px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/14315i101DA6EF87AC9DDE/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;the output shows doman name\usernames&lt;/P&gt;&lt;P&gt;so it is ok&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 10:29:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206284#M60540</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-03-19T10:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206294#M60542</link>
      <description>&lt;P&gt;are you seeing these same source ports appear in your firewall's sessions from that server's IP address ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;except for a handful of 'system' services like SMB, every normal user session should be sourced from those source ports. if you see different source ports, you may need to check if htere's a proxy, webfiltering or AV service installed on the server that could intercept outgoing connections and alter the source port once more&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 11:05:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206294#M60542</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-19T11:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206295#M60543</link>
      <description>I will check it&lt;BR /&gt;I also used to ping 8.8.8.8 by logging in with one of the users credentials .But in logs i only see the source ip of terminal server and no user</description>
      <pubDate>Mon, 19 Mar 2018 11:10:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206295#M60543</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-03-19T11:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206296#M60544</link>
      <description>&lt;P&gt;well ... ping is a system service .... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 11:11:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206296#M60544</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-19T11:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206297#M60545</link>
      <description>Ok...&lt;BR /&gt;But what is best way to check it? Just type something in browser?make http request ?</description>
      <pubDate>Mon, 19 Mar 2018 11:14:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206297#M60545</guid>
      <dc:creator>Radmin_85</dc:creator>
      <dc:date>2018-03-19T11:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206298#M60546</link>
      <description>&lt;P&gt;yes, try browsing to&amp;nbsp;a common website like cnn or wikipedia&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 11:17:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/206298#M60546</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2018-03-19T11:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Terminal server user identification</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/384027#M90011</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you remember the last situation of this problem ? were you able to solve it ?(and how)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Feb 2021 06:56:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/terminal-server-user-identification/m-p/384027#M90011</guid>
      <dc:creator>Retired Member</dc:creator>
      <dc:date>2021-02-05T06:56:58Z</dc:date>
    </item>
  </channel>
</rss>

