<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User ID agent user-IP mapping refresh evets in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207596#M60831</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;Thanks for your explianation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In point 3, what I mean lets say the cache time on agent is 8 hours. So in the morning user login to DC and firewall gets the user-ip mapping from agent and user is good. In evening, the user did not lock his machine and left. In the next morning, oviously user-agent does not have mapping (due to 8 hours passed) and usesr did&amp;nbsp; not login because he left his pc unlock.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, your solution is capative portal?&lt;/P&gt;&lt;P&gt;If I use exchange logs also with agent as&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned then it wills solve the issue?&lt;/P&gt;</description>
    <pubDate>Tue, 27 Mar 2018 06:11:55 GMT</pubDate>
    <dc:creator>faizankhurshid</dc:creator>
    <dc:date>2018-03-27T06:11:55Z</dc:date>
    <item>
      <title>User ID agent user-IP mapping refresh evets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207387#M60799</link>
      <description>&lt;P&gt;Hi Experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you know the default cache time for user-IP mapping in user-ID agent is 45 minutes. If I am not using WMI or netbios or server session monitoring then:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1- How user-IP mapping&amp;nbsp;can be maintained by user-ID agent?&amp;nbsp;This means user has to logout and login again after every 45 minutes? Can I increase this to 10 hours to cover the office timing?&lt;/P&gt;&lt;P&gt;2- At the end of day, user normally lock the machine (instead of logout) and in next morning he unlock and login to machine. Will this&amp;nbsp;generate the authentication event in AD and refresh the user-IP mapping in user-ID agent?&lt;/P&gt;&lt;P&gt;3- What if user even does not lock the machine and there is no auto-lock policy then next monring there will be no user-IP mapping in agent. Then user has to logout and login again?&lt;/P&gt;&lt;P&gt;4- What if there is 'cache domain login policy' then there will be no authentication event in AD and agent does not have any clue. What I can do in this scenario?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 11:39:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207387#M60799</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-26T11:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: User ID agent user-IP mapping refresh evets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207454#M60814</link>
      <description>&lt;P&gt;1. you can set this to 24 hours if you like...&amp;nbsp; preference seems to be 4 to 8 hours but it's up to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. yes windows lock and unlock triggers an event in AD providing the device is on the DC network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3 + 4. what do your users do all day... if nothing then you dont need user-id mapping..&amp;nbsp; if you need the user mapping for firewall access then add captive portal with sso.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 15:07:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207454#M60814</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-26T15:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: User ID agent user-IP mapping refresh evets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207534#M60825</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;If you use Exchange, I recommend using its logs as well. Outlook clinets are always authenticating against it. This way the rest of the points dont really need to happen and its quicker to update, if users move around.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Mar 2018 21:55:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207534#M60825</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2018-03-26T21:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: User ID agent user-IP mapping refresh evets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207596#M60831</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;Thanks for your explianation.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In point 3, what I mean lets say the cache time on agent is 8 hours. So in the morning user login to DC and firewall gets the user-ip mapping from agent and user is good. In evening, the user did not lock his machine and left. In the next morning, oviously user-agent does not have mapping (due to 8 hours passed) and usesr did&amp;nbsp; not login because he left his pc unlock.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, your solution is capative portal?&lt;/P&gt;&lt;P&gt;If I use exchange logs also with agent as&amp;nbsp;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;mentioned then it wills solve the issue?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 06:11:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207596#M60831</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-27T06:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: User ID agent user-IP mapping refresh evets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207655#M60840</link>
      <description>&lt;P&gt;Ok for point 3. A user can leave his device overnight and it will not auto lock.&lt;/P&gt;&lt;P&gt;perhaps a data protection training video is required here....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes if your timeout is 8 hours and the user has no domain activity overnight then it will timeout.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i would go for&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;suggestion before captive portal. Several other forum users have opted for this as a solution for user mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;do you have any particular reason for no auto lock after inactivity...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 12:42:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207655#M60840</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-03-27T12:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: User ID agent user-IP mapping refresh evets</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207718#M60849</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;Thanks. Actually there is auto-lock policy in place, I just want to understand the concept if there is no domain activity then what we can do.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 21:00:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-agent-user-ip-mapping-refresh-evets/m-p/207718#M60849</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-03-27T21:00:42Z</dc:date>
    </item>
  </channel>
</rss>

