<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User-ID based policies exclusion in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214547#M62338</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to enable user-id features in all security policies. But I have a question, from users to Domain controller, I should not use user-id feature? as firewall does not know about user-ip mapping untill users are login to domain controller?&lt;/P&gt;&lt;P&gt;Also on which security rules, I should not enable user-ID?&lt;/P&gt;</description>
    <pubDate>Thu, 17 May 2018 10:06:59 GMT</pubDate>
    <dc:creator>faizankhurshid</dc:creator>
    <dc:date>2018-05-17T10:06:59Z</dc:date>
    <item>
      <title>User-ID based policies exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214547#M62338</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to enable user-id features in all security policies. But I have a question, from users to Domain controller, I should not use user-id feature? as firewall does not know about user-ip mapping untill users are login to domain controller?&lt;/P&gt;&lt;P&gt;Also on which security rules, I should not enable user-ID?&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 10:06:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214547#M62338</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-05-17T10:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID based policies exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214574#M62340</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;...But I have a question, from users to Domain controller, I should not use user-id feature? as firewall does not know about user-ip mapping untill users are login to domain controller?&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you clarify this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Also on which security rules, I should not enable user-ID?"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There's really no scenario where you wouldn't want it.&amp;nbsp; It's always good to have that additional bit of granularity of access control.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That said there might be scenarios where process are executing the network access and thus no "logged in" user is actually executing the traffic.&amp;nbsp; This would be a scenario where user-id controls will not work.&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 15:32:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214574#M62340</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2018-05-17T15:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID based policies exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214581#M62342</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/5300"&gt;@Brandon_Wertz&lt;/a&gt;&amp;nbsp;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For This "&lt;SPAN&gt;But I have a question, from users to Domain controller, I should not use user-id feature? as firewall does not know about user-ip mapping untill users are login to domain controller?"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What I mean is,&amp;nbsp; lets say users are in trust zone and domain controller are in server zone.&amp;nbsp; I need to make policy to allow users to communicate with DC then this policy I should not use user-ID?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 15:51:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214581#M62342</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-05-17T15:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID based policies exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214601#M62345</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;That would be one example; as if the machine has reached user-id age-out and you are restricting access to the domain controllers as 'known-users' for example, this would start denying the traffic.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 16:43:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214601#M62345</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2018-05-17T16:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID based policies exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214608#M62347</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/43480"&gt;@BPry&lt;/a&gt;&amp;nbsp; So users to DC policies, I should not enable user-id?&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 18:35:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214608#M62347</guid>
      <dc:creator>faizankhurshid</dc:creator>
      <dc:date>2018-05-17T18:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: User-ID based policies exclusion</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214609#M62348</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/82863"&gt;@faizankhurshid&lt;/a&gt;&amp;nbsp;exactly, towards your domain controllers you shouldn't enforce User-ID. In addition printservers, profileshares and other mapped network drives are also critical connections. It is possible to enable user-ID there but you have to make sure that the User-IDs are almost instantly present on the firewalls because otherwise it takes a lot longer for the users to log in as windows receives the information on what to do with the group policies and then it tries to to this. And if the connection is not possible pretty fast then windows tries again and again and again - so in this case it could take a lot longer for the users to log in. So to enable there make sure that the log-read frequency of the domain conteoller logs is set to 1 second (the lowest possible value).&lt;/P&gt;</description>
      <pubDate>Thu, 17 May 2018 19:30:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/user-id-based-policies-exclusion/m-p/214609#M62348</guid>
      <dc:creator>Remo</dc:creator>
      <dc:date>2018-05-17T19:30:05Z</dc:date>
    </item>
  </channel>
</rss>

